CVE-2018-14608 Details
Description
Thomson Reuters UltraTax CS 2017 on Windows has a password protection option; however, the level of protection might be inconsistent with some customers' expectations because the data is directly accessible in cleartext. Specifically, it stores customer data in unique directories (%install_path%\WinCSI\UT17DATA\client_ID\file_name.XX17) that can be bypassed without authentication by examining the strings of the .XX17 file. The strings stored in the .XX17 file contain each customer's: Full Name, Spouse's Name, Social Security Number, Date of Birth, Occupation, Home Address, Daytime Phone Number, Home Phone Number, Spouse's Address, Spouse's Daytime Phone Number, Spouse's Social Security Number, Spouse's Home Phone Number, Spouse's Occupation, Spouse's Date of Birth, and Spouse's Filing Status.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://corporateblue.com/ultratax-cs-data-exposure-vulnerability/ | CVE | ExploitThird Party AdvisoryURL Repurposed |
| https://www.themikewylie.com/ultratax-cs-data-exposure-vulnerability-cve-2018-14608-cve-2018-14607/ | CVE | |
| https://corporateblue.com/ultratax-cs-data-exposure-vulnerability/ | [email protected] | ExploitThird Party AdvisoryURL Repurposed |
| https://www.themikewylie.com/ultratax-cs-data-exposure-vulnerability-cve-2018-14608-cve-2018-14607/ | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-311 | Missing Encryption of Sensitive Data | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| thomsonreuters ultratax cs | 2017 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
8 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Feb 14, 2024 | Reference Tag Update | [email protected] |
| Oct 3, 2019 | CWE Remap | [email protected] |
| Sep 30, 2019 | CVE Modified | [email protected] |
| Oct 4, 2018 | Initial Analysis | [email protected] |
| Jul 28, 2018 | CVE Modified | [email protected] |