CVE-2018-14608
Last modified
CVE-2018-14608 is a vulnerability of currently unknown severity. Thomson Reuters UltraTax CS 2017 on Windows has a password protection option; however, the level of protection might be inconsistent with some customers' expectations because the data is directly accessible in cleartext. Specifically, it stores customer data in unique directories (%install_path%\WinCSI\UT17DATA\client_ID\file_name.XX17) that can be bypassed without authentication by examining the strings of the .XX17 file. EPSS estimates a 0.88% chance of exploitation in the next 30 days.
Description
Thomson Reuters UltraTax CS 2017 on Windows has a password protection option; however, the level of protection might be inconsistent with some customers' expectations because the data is directly accessible in cleartext. Specifically, it stores customer data in unique directories (%install_path%\WinCSI\UT17DATA\client_ID\file_name.XX17) that can be bypassed without authentication by examining the strings of the .XX17 file. The strings stored in the .XX17 file contain each customer's: Full Name, Spouse's Name, Social Security Number, Date of Birth, Occupation, Home Address, Daytime Phone Number, Home Phone Number, Spouse's Address, Spouse's Daytime Phone Number, Spouse's Social Security Number, Spouse's Home Phone Number, Spouse's Occupation, Spouse's Date of Birth, and Spouse's Filing Status.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Thomsonreuters | Ultratax Cs | 2017 |
References
- https://corporateblue.com/ultratax-cs-data-exposure-vulnerability/Exploit, Third Party Advisory, URL Repurposed
- https://corporateblue.com/ultratax-cs-data-exposure-vulnerability/Exploit, Third Party Advisory, URL Repurposed
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-14608?
How severe is CVE-2018-14608?
How do I fix CVE-2018-14608?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-14602An issue was discovered in GitLab Community and Enterprise E…
- CVE-2018-14603An issue was discovered in GitLab Community and Enterprise E…
- CVE-2018-14604An issue was discovered in GitLab Community and Enterprise E…
- CVE-2018-14605An issue was discovered in GitLab Community and Enterprise E…
- CVE-2018-14606An issue was discovered in GitLab Community and Enterprise E…
- CVE-2018-14607Thomson Reuters UltraTax CS 2017 on Windows, in a client/ser…
- CVE-2018-14609An issue was discovered in the Linux kernel through 4.17.10.…
- CVE-2018-1461IBM SAN Volume Controller, IBM Storwize, IBM Spectrum Virtua…5.4
- CVE-2018-14610An issue was discovered in the Linux kernel through 4.17.10.…
- CVE-2018-14611An issue was discovered in the Linux kernel through 4.17.10.…
- CVE-2018-14612An issue was discovered in the Linux kernel through 4.17.10.…
- CVE-2018-14613An issue was discovered in the Linux kernel through 4.17.10.…
Are you affected by CVE-2018-14608?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
