Unrated severityNVD Advisory· Published Dec 2, 2014· Updated May 6, 2026
CVE-2014-9113
CVE-2014-9113
Description
CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Users: Modify and Write) for the (1) Pfx.Engagement.WcfServices, (2) PFXEngDesktopService, (3) PFXSYNPFTService, and (4) P2EWinService service files in PFX Engagement\, which allows local users to obtain LocalSystem privileges via a Trojan horse file.
Affected products
1- cpe:2.3:a:cchgroup:prosystem_fx_engagement:*:*:*:*:*:*:*:*Range: <=7.1
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
3News mentions
0No linked articles in our index yet.