Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
N/A
Vulnerability Description
The installer in Thomson Reuters Fixed Assets CS 13.1.4 and earlier uses weak permissions for connectbgdl.exe, which allows local users to execute arbitrary code by modifying this program.
CVSS Information
N/A
Vulnerability Type
N/A
Vulnerability Title
Thomson Reuters Fixed Assets CS 任意代码执行漏洞
Vulnerability Description
Thomson Reuters Fixed Assets CS是美国汤森路透(Thomson Reuters)公司的一套资产管理软件。该软件支持创建资产图表、跟踪资产处理过程和生成资产统计报告等。 Thomson Reuters Fixed Assets CS 13.1.4及之前版本的安装程序中存在安全漏洞,该漏洞源于程序对connectbgdl.exe文件分配弱权限。本地攻击者可通过修改程序利用该漏洞执行任意代码。
CVSS Information
N/A
Vulnerability Type
N/A