Thomson Reuters operates a portfolio of financial, legal, and compliance software platforms including FATCA, Concourse Matter Room, Eikon, Firm Central Desktop, and Fixed Assets CS, serving business-critical functions across institutional clients. Vulnerabilities affecting the vendor skew strongly toward critical-severity outcomes and frequently acquire public exploit code, reflecting the high-value nature of the data and systems these platforms protect. The exposure recurs through structural weakness classes including path traversal, missing encryption of sensitive data, code injection, incorrect default permissions, and unrestricted file uploads—issues endemic to complex enterprise software handling confidential information. Current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Thomsonreuters over time
Signals from CVEs in this vendor scope (8 CVEs).
8 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2013-5912HIGH VhttpdMgr in Thomson Reuters Velocity Analytics Vhayu Analytic Server 6.94 build 2995 allows remote attackers to execute arbitrary code via a URL in the fileName parameter during a | Nov 28, 2013 | 10.0 | 52 | NO | YES |
CVE-2019-8385CRITICAL An issue was discovered in Thomson Reuters Desktop Extensions 1.9.0.358. An unauthenticated directory traversal and local file inclusion vulnerability in the ThomsonReuters.Desktop | Jun 5, 2019 | 9.8 | 51 | NO | YES |
CVE-2015-5951CRITICAL A file upload issue exists in the specid parameter in Thomson Reuters FATCH before 5.2, which allows malicious users to upload arbitrary PHP files to the web root and execute syste | Jan 6, 2020 | 9.9 | 30 | NO | NO |
CVE-2014-9141HIGH The installer in Thomson Reuters Fixed Assets CS 13.1.4 and earlier uses weak permissions for connectbgdl.exe, which allows local users to execute arbitrary code by modifying this | Dec 3, 2014 | 7.2 | 27 | NO | YES |
CVE-2019-10679HIGH Thomson Reuters Eikon 4.0.42144 allows all local users to modify the service executable file because of weak %PROGRAMFILES(X86)%\Thomson Reuters\Eikon permissions. | Sep 3, 2020 | 7.8 | 25 | NO | NO |
CVE-2015-5952CRITICAL Directory traversal vulnerability in Thomson Reuters for FATCA before 5.2 allows remote attackers to execute arbitrary files via the item parameter. | Jan 15, 2020 | 9.8 | 25 | NO | NO |
CVE-2018-14608HIGH Thomson Reuters UltraTax CS 2017 on Windows has a password protection option; however, the level of protection might be inconsistent with some customers' expectations because the d | Jul 26, 2018 | 7.5 | 24 | NO | NO |
CVE-2018-14607HIGH Thomson Reuters UltraTax CS 2017 on Windows, in a client/server configuration, transfers customer records and bank account numbers in cleartext over SMBv2, which allows attackers t | Jul 26, 2018 | 7.5 | 24 | NO | NO |
Signals from CVEs in this vendor scope (8 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Thomsonreuters.
Media articles that mention a CVE ID that affects a product developed by Thomsonreuters — matched by CVE ID, not by vendor name.