Learn about CVE-2018-14607 affecting Thomson Reuters UltraTax CS 2017 on Windows. Discover the impact, technical details, and mitigation steps for this data exposure vulnerability.
Thomson Reuters UltraTax CS 2017 on Windows, in a client/server setup, exposes sensitive customer data due to cleartext transmission over SMBv2.
Understanding CVE-2018-14607
Thomson Reuters UltraTax CS 2017 on Windows is vulnerable to data exposure risks when used in a client/server configuration.
What is CVE-2018-14607?
The vulnerability in Thomson Reuters UltraTax CS 2017 allows for the transmission of customer records and bank account numbers without encryption over SMBv2, potentially leading to unauthorized access to sensitive information.
The Impact of CVE-2018-14607
The security flaw enables attackers to intercept confidential data, including Client ID, Social Security Numbers, and other personal details, by monitoring the network or executing man-in-the-middle attacks.
Technical Details of CVE-2018-14607
Thomson Reuters UltraTax CS 2017 vulnerability specifics.
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
Protecting systems from CVE-2018-14607.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates