PoC Index

CVE-2014-9141

HIGH 7.2EPSS 1.2%

The installer in Thomson Reuters Fixed Assets CS 13.1.4 and earlier uses weak permissions for connectbgdl.exe, which allows local users to execute arbitrary code by modifying this program.

CVSS v2.0
7.2 HIGHAV:L/AC:L/Au:N/C:C/I:C/A:C
EPSS
1.21% chance of exploitation in the next 30 days, 66th percentile
Published
2014-12-03
Updated
2024-08-06

Proof-of-concept exploits (1)

ExploitDB entries (1)

References

Related