The installer in Thomson Reuters Fixed Assets CS 13.1.4 and earlier uses weak permissions for connectbgdl.exe, which allows local users to execute arbitrary code by modifying this program.
References
Configurations
Information
Published : 2014-12-02 17:59
Updated : 2014-12-17 08:17
NVD link : CVE-2014-9141
Mitre link : CVE-2014-9141
JSON object : View
CWE
CWE-264
Permissions, Privileges, and Access Controls
Products Affected
thomsonreuters
- fixed_assets_cs