DLL Hijacking Vulnerability in Trend Micro Password Manager
CVE-2019-14684
7.8HIGH
Key Information:
- Vendor
- Trend Micro
- Vendor
- CVE Published:
- 20 August 2019
Summary
A DLL hijacking vulnerability has been identified in Trend Micro Password Manager 5.0, which allows attackers to exploit the service by loading an arbitrary unsigned DLL into the process of the signed service. If successfully executed, it can lead to unauthorized access and manipulation of sensitive information. Users are urged to apply necessary updates and follow security best practices to mitigate the risks associated with this vulnerability.
Affected Version(s)
Trend Micro Password Manager 2019 (5.0)
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved