CVE-2014-9113
Status: ModifiedHigh (7.2)—💥 Exploit
CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Users: Modify and Write) for the (1) Pfx.Engagement.WcfServices, (2) PFXEngDesktopService, (3) PFXSYNPFTService, and (4) P2EWinService service files in PFX Engagement\, which allows local users to obtain LocalSystem privileges via a Trojan horse file.
CVSS
- Version: 2.0
- Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C
- Base score: 7.2
Exploitation probability (EPSS)
- Probability of exploitation in the next 30 days: 1.71%
- Percentile among all scored CVEs: 77
- Score date: 10/7/2026
EPSS (Exploit Prediction Scoring System, FIRST) estimates how likely a vulnerability is to be exploited in the wild within 30 days. It complements CVSS (impact) and CISA KEV (confirmed exploitation).
💥 Public exploits
Exploit code or detection templates are publicly available. This is not the same as confirmed active exploitation (KEV), but it raises the risk: patch with priority.
- Published on Exploit-DB · CCH Wolters Kluwer PFX Engagement 7.1 - Local Privilege Escalation (11/28/2014)
Affected technologies (1)
CWEs
- CWE-264
References
- http://packetstormsecurity.com/files/129323/CCH-Wolters-Kluwer-PFX-Engagement-7.1-Privilege-Escalation.html
- http://www.exploit-db.com/exploits/35395
- http://www.information-paradox.net/2014/11/cve-2014-9113-cch-wolters-kluwer-pfx.html
- http://packetstormsecurity.com/files/129323/CCH-Wolters-Kluwer-PFX-Engagement-7.1-Privilege-Escalation.html
- http://www.exploit-db.com/exploits/35395
- http://www.information-paradox.net/2014/11/cve-2014-9113-cch-wolters-kluwer-pfx.html
Raw JSON (NVD)
Show
{
"id": "CVE-2014-9113",
"cveTags": [],
"metrics": {
"cvssMetricV2": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"version": "2.0",
"baseScore": 7.2,
"accessVector": "LOCAL",
"vectorString": "AV:L/AC:L/Au:N/C:C/I:C/A:C",
"authentication": "NONE",
"integrityImpact": "COMPLETE",
"accessComplexity": "LOW",
"availabilityImpact": "COMPLETE",
"confidentialityImpact": "COMPLETE"
},
"acInsufInfo": false,
"impactScore": 10,
"baseSeverity": "HIGH",
"obtainAllPrivilege": false,
"exploitabilityScore": 3.9,
"obtainUserPrivilege": false,
"obtainOtherPrivilege": false,
"userInteractionRequired": false
}
]
},
"affected": [
{
"source": "cve@mitre.org",
"affectedData": [
{
"vendor": "n/a",
"product": "n/a",
"versions": [
{
"status": "affected",
"version": "n/a"
}
]
}
]
}
],
"published": "2014-12-02T16:59:07.010",
"references": [
{
"url": "http://packetstormsecurity.com/files/129323/CCH-Wolters-Kluwer-PFX-Engagement-7.1-Privilege-Escalation.html",
"source": "cve@mitre.org"
},
{
"url": "http://www.exploit-db.com/exploits/35395",
"source": "cve@mitre.org"
},
{
"url": "http://www.information-paradox.net/2014/11/cve-2014-9113-cch-wolters-kluwer-pfx.html",
"tags": [
"Exploit"
],
"source": "cve@mitre.org"
},
{
"url": "http://packetstormsecurity.com/files/129323/CCH-Wolters-Kluwer-PFX-Engagement-7.1-Privilege-Escalation.html",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.exploit-db.com/exploits/35395",
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "http://www.information-paradox.net/2014/11/cve-2014-9113-cch-wolters-kluwer-pfx.html",
"tags": [
"Exploit"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-264"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "CCH Wolters Kluwer ProSystem fx Engagement (aka PFX Engagement) 7.1 and earlier uses weak permissions (Authenticated Users: Modify and Write) for the (1) Pfx.Engagement.WcfServices, (2) PFXEngDesktopService, (3) PFXSYNPFTService, and (4) P2EWinService service files in PFX Engagement\\, which allows local users to obtain LocalSystem privileges via a Trojan horse file."
},
{
"lang": "es",
"value": "CCH Wolters Kluwer ProSystem fx Engagement (también conocido como PFX Engagement) 7.1 y anteriores utiliza permisos débiles (usuarios autenticados: modificar y escribir) para los ficheros de servicio (1) Pfx.Engagement.WcfServices, (2) PFXEngDesktopService, (3) PFXSYNPFTService, y (4) P2EWinService en PFX Engagement\\, lo que permite a usuarios locales obtener privilegios LocalSystem a través de un fichero troyano."
}
],
"lastModified": "2026-06-17T00:17:46.797",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:cchgroup:prosystem_fx_engagement:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "F420358E-905F-4F51-A4E9-8630E69568D8",
"versionEndIncluding": "7.1"
}
],
"operator": "OR"
}
]
}
],
"vendorComments": [
{
"comment": "A security update has been released on 12/03/2014 to address the vulnerability in CCH Wolters Kluwer ProSystem fx Engagement. This update corrects the permissions on necessary application services. Please see the online release bulletin for instructions on how to apply the security update. \n<a href=\"https://support.cch.com/updates/Engagement/pdf/Services%20Security%20Update%20-%20Release%20Bulletin%20-%20US.pdf\" rel=\"nofollow\">https://support.cch.com/updates/Engagement/pdf/Services%20Security%20Update%20-%20Release%20Bulletin%20-%20US.pdf</a>",
"lastModified": "2014-12-15T13:55:03.083",
"organization": "CCH Group"
}
],
"sourceIdentifier": "cve@mitre.org"
}