Vulnerability Description
Untrusted search path vulnerability in CmnView.exe in CIMON CmnView 2.14.0.1 and 3.x before UltimateAccess 3.02 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Cimon | Cmnview | <= 2.14.0.1 |
| Cimon | Ultimateaccess | <= 3.01 |
References
- https://ics-cert.us-cert.gov/advisories/ICSA-15-069-01Third Party AdvisoryUS Government Resource
- https://ics-cert.us-cert.gov/advisories/ICSA-15-069-01Third Party AdvisoryUS Government Resource
FAQ
What is CVE-2014-9207?
CVE-2014-9207 is a vulnerability with a CVSS score of 6.9 (MEDIUM). Untrusted search path vulnerability in CmnView.exe in CIMON CmnView 2.14.0.1 and 3.x before UltimateAccess 3.02 allows local users to gain privileges via a Trojan horse DLL in the current working dire...
How severe is CVE-2014-9207?
CVE-2014-9207 has been rated MEDIUM with a CVSS base score of 6.9/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2014-9207?
Check the references section above for vendor advisories and patch information. Affected products include: Cimon Cmnview, Cimon Ultimateaccess.