{"api_version":"1","generated_at":"2026-07-23T10:14:41+00:00","cve":"CVE-2014-9113","urls":{"html":"https://cve.report/CVE-2014-9113","api":"https://cve.report/api/cve/CVE-2014-9113.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2014-9113","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2014-9113"},"summary":{"title":"CVE-2014-9113","description":"CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Users: Modify and Write) for the (1) Pfx.Engagement.WcfServices, (2) PFXEngDesktopService, (3) PFXSYNPFTService, and (4) P2EWinService service files in PFX Engagement\\, which allows local users to obtain LocalSystem privileges via a Trojan horse file.","state":"PUBLISHED","assigner":"mitre","published_at":"2014-12-02 16:59:07","updated_at":"2026-05-06 22:30:45"},"problem_types":["CWE-264","n/a"],"metrics":[{"version":"2.0","source":"nvd@nist.gov","type":"Primary","score":"7.2","severity":"","vector":"AV:L/AC:L/Au:N/C:C/I:C/A:C","data":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"}}],"references":[{"url":"http://www.information-paradox.net/2014/11/cve-2014-9113-cch-wolters-kluwer-pfx.html","name":"http://www.information-paradox.net/2014/11/cve-2014-9113-cch-wolters-kluwer-pfx.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":["Exploit"],"title":"Information Paradox: CVE-2014-9113 : CCH Wolters Kluwer PFX Engagement <= v7.1 Local Privilege Escalation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://packetstormsecurity.com/files/129323/CCH-Wolters-Kluwer-PFX-Engagement-7.1-Privilege-Escalation.html","name":"http://packetstormsecurity.com/files/129323/CCH-Wolters-Kluwer-PFX-Engagement-7.1-Privilege-Escalation.html","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"CCH Wolters Kluwer PFX Engagement 7.1 Privilege Escalation ≈ Packet Storm","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"http://www.exploit-db.com/exploits/35395","name":"http://www.exploit-db.com/exploits/35395","refsource":"af854a3a-2127-422b-91ae-364da2661108","tags":[],"title":"CCH Wolters Kluwer PFX Engagement <= 7.1 - Local Privilege Escalation","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2014-9113","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2014-9113","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[{"source":"CNA","vendor":"n/a","product":"n/a","version":"affected n/a","platforms":[]}],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2014","cve_id":"9113","vulnerable":"1","versionEndIncluding":"7.1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"cchgroup","cpe5":"prosystem_fx_engagement","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[{"cvename":"CVE-2014-9113","organization":"CCH Group","lastmodified":"2014-12-15","contributor":"Srinivasu Maradana","statementText":"A security update has been released on 12/03/2014 to address the vulnerability in CCH Wolters Kluwer ProSystem fx Engagement. This update corrects the permissions on necessary application services. Please see the online release bulletin for instructions on how to apply the security update. <a href=\"https://support.cch.com/updates/Engagement/pdf/Services%20Security%20Update%20-%20Release%20Bulletin%20-%20US.pdf\" rel=\"nofollow\">https://support.cch.com/updates/Engagement/pdf/Services%20Security%20Update%20-%20Release%20Bulletin%20-%20US.pdf</a>","cve_year":"2014","cve_id":"9113","crc32":"10ad4de0"}],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"containers":{"adp":[{"providerMetadata":{"dateUpdated":"2024-08-06T13:33:13.426Z","orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE"},"references":[{"name":"35395","tags":["exploit","x_refsource_EXPLOIT-DB","x_transferred"],"url":"http://www.exploit-db.com/exploits/35395"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://packetstormsecurity.com/files/129323/CCH-Wolters-Kluwer-PFX-Engagement-7.1-Privilege-Escalation.html"},{"tags":["x_refsource_MISC","x_transferred"],"url":"http://www.information-paradox.net/2014/11/cve-2014-9113-cch-wolters-kluwer-pfx.html"}],"title":"CVE Program Container"}],"cna":{"affected":[{"product":"n/a","vendor":"n/a","versions":[{"status":"affected","version":"n/a"}]}],"datePublic":"2014-11-26T00:00:00.000Z","descriptions":[{"lang":"en","value":"CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Users: Modify and Write) for the (1) Pfx.Engagement.WcfServices, (2) PFXEngDesktopService, (3) PFXSYNPFTService, and (4) P2EWinService service files in PFX Engagement\\, which allows local users to obtain LocalSystem privileges via a Trojan horse file."}],"problemTypes":[{"descriptions":[{"description":"n/a","lang":"en","type":"text"}]}],"providerMetadata":{"dateUpdated":"2014-12-02T15:57:01.000Z","orgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","shortName":"mitre"},"references":[{"name":"35395","tags":["exploit","x_refsource_EXPLOIT-DB"],"url":"http://www.exploit-db.com/exploits/35395"},{"tags":["x_refsource_MISC"],"url":"http://packetstormsecurity.com/files/129323/CCH-Wolters-Kluwer-PFX-Engagement-7.1-Privilege-Escalation.html"},{"tags":["x_refsource_MISC"],"url":"http://www.information-paradox.net/2014/11/cve-2014-9113-cch-wolters-kluwer-pfx.html"}],"x_legacyV4Record":{"CVE_data_meta":{"ASSIGNER":"cve@mitre.org","ID":"CVE-2014-9113","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"n/a","version":{"version_data":[{"version_value":"n/a"}]}}]},"vendor_name":"n/a"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Users: Modify and Write) for the (1) Pfx.Engagement.WcfServices, (2) PFXEngDesktopService, (3) PFXSYNPFTService, and (4) P2EWinService service files in PFX Engagement\\, which allows local users to obtain LocalSystem privileges via a Trojan horse file."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"n/a"}]}]},"references":{"reference_data":[{"name":"35395","refsource":"EXPLOIT-DB","url":"http://www.exploit-db.com/exploits/35395"},{"name":"http://packetstormsecurity.com/files/129323/CCH-Wolters-Kluwer-PFX-Engagement-7.1-Privilege-Escalation.html","refsource":"MISC","url":"http://packetstormsecurity.com/files/129323/CCH-Wolters-Kluwer-PFX-Engagement-7.1-Privilege-Escalation.html"},{"name":"http://www.information-paradox.net/2014/11/cve-2014-9113-cch-wolters-kluwer-pfx.html","refsource":"MISC","url":"http://www.information-paradox.net/2014/11/cve-2014-9113-cch-wolters-kluwer-pfx.html"}]}}}},"cveMetadata":{"assignerOrgId":"8254265b-2729-46b6-b9e3-3dfca2d5bfca","assignerShortName":"mitre","cveId":"CVE-2014-9113","datePublished":"2014-12-02T16:00:00.000Z","dateReserved":"2014-11-26T00:00:00.000Z","dateUpdated":"2024-08-06T13:33:13.426Z","state":"PUBLISHED"},"dataType":"CVE_RECORD","dataVersion":"5.1"},"nvd":{"publishedDate":"2014-12-02 16:59:07","lastModifiedDate":"2026-05-06 22:30:45","problem_types":["CWE-264","n/a"],"metrics":{"cvssMetricV2":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"2.0","vectorString":"AV:L/AC:L/Au:N/C:C/I:C/A:C","baseScore":7.2,"accessVector":"LOCAL","accessComplexity":"LOW","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE"},"baseSeverity":"HIGH","exploitabilityScore":3.9,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}]},"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:cchgroup:prosystem_fx_engagement:*:*:*:*:*:*:*:*","versionEndIncluding":"7.1","matchCriteriaId":"F420358E-905F-4F51-A4E9-8630E69568D8"}]}]}]},"legacy_mitre":{"record":{"CveYear":"2014","CveId":"9113","Ordinal":"1","Title":"CVE-2014-9113","CVE":"CVE-2014-9113","Year":"2014"},"notes":[{"CveYear":"2014","CveId":"9113","Ordinal":"1","NoteData":"CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Users: Modify and Write) for the (1) Pfx.Engagement.WcfServices, (2) PFXEngDesktopService, (3) PFXSYNPFTService, and (4) P2EWinService service files in PFX Engagement\\, which allows local users to obtain LocalSystem privileges via a Trojan horse file.","Type":"Description","Title":"CVE-2014-9113"},{"CveYear":"2014","CveId":"9113","Ordinal":"2","NoteData":"2014-12-02","Type":"Other","Title":"Published"},{"CveYear":"2014","CveId":"9113","Ordinal":"3","NoteData":"2014-12-02","Type":"Other","Title":"Modified"}]}}}