Back to Database
Status published
High
CVE-2019-10679
Thomson Reuters Eikon 4.0.42144 allows all local users to modify...
Vulnerability Description
Thomson Reuters Eikon 4.0.42144 allows all local users to modify the service executable file because of weak %PROGRAMFILES(X86)%\Thomson Reuters\Eikon permissions.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2019-10679
Credits & Attribution
No credits recorded in the NVD database.
References
- https://www.thomsonreuters.com/en/products-services.html
- https://www.sec-consult.com/en/vulnerability-lab/advisories/index.html
- http://seclists.org/fulldisclosure/2020/Aug/19
- http://packetstormsecurity.com/files/158989/Eikon-Thomson-Reuters-4.0.42144-File-Permissions.html
- https://sec-consult.com/en/blog/advisories/extensive-file-permissions-on-service-executable-in-eikon-thomson-reuters-cve-2019-10679/
More from thomsonreuters
View All →CVE-2019-8385
An issue was discovered in Thomson Reuters Desktop Extensions 1.9.0.358....
Critical
9.8
CVE-2018-14608
Thomson Reuters UltraTax CS 2017 on Windows has a password...
High
7.5
CVE-2018-14607
Thomson Reuters UltraTax CS 2017 on Windows, in a client/server...
High
7.5
CVE-2015-5952
Directory traversal vulnerability in Thomson Reuters for FATCA before 5.2...
Critical
9.8
CVE-2015-5951
A file upload issue exists in the specid parameter in...
Critical
9.9
Affected Vendor
thomsonreuters
View all reports →Affected Software
eikon
Vulnerable Versions:
4.0.42144
Timeline
Official Publish:
September 3rd, 2020
Last Modified:
August 4th, 2024
Added to House:
July 20th, 2026
CVSS Vectors
V3:
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weaknesses (CWE)
No CWE data available
MITRE ATT&CK TTPs
No associated TTPs found for this vulnerability.