CVE-2018-14608
Last modified
CVE-2018-14608 is a vulnerability of currently unknown severity. Thomson Reuters UltraTax CS 2017 on Windows has a password protection option; however, the level of protection might be inconsistent with some customers' expectations because the data is directly accessible in cleartext. Specifically, it stores customer data in unique directories (%install_path%\WinCSI\UT17DATA\client_ID\file_name.XX17) that can be bypassed without authentication by examining the strings of the .XX17 file. EPSS estimates a 0.88% chance of exploitation in the next 30 days.
Description
Thomson Reuters UltraTax CS 2017 on Windows has a password protection option; however, the level of protection might be inconsistent with some customers' expectations because the data is directly accessible in cleartext. Specifically, it stores customer data in unique directories (%install_path%\WinCSI\UT17DATA\client_ID\file_name.XX17) that can be bypassed without authentication by examining the strings of the .XX17 file. The strings stored in the .XX17 file contain each customer's: Full Name, Spouse's Name, Social Security Number, Date of Birth, Occupation, Home Address, Daytime Phone Number, Home Phone Number, Spouse's Address, Spouse's Daytime Phone Number, Spouse's Social Security Number, Spouse's Home Phone Number, Spouse's Occupation, Spouse's Date of Birth, and Spouse's Filing Status.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Thomsonreuters | Ultratax Cs | 2017 |
References
- https://corporateblue.com/ultratax-cs-data-exposure-vulnerability/Exploit, Third Party Advisory, URL Repurposed
- https://corporateblue.com/ultratax-cs-data-exposure-vulnerability/Exploit, Third Party Advisory, URL Repurposed
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-14608?
How severe is CVE-2018-14608?
How do I fix CVE-2018-14608?
Are you affected by CVE-2018-14608?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
