CVE-2019-14684
Summary
| CVE | CVE-2019-14684 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-08-20 14:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14687. |
Risk And Classification
Problem Types: CWE-427
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Trendmicro | Password Manager | 5.0 | All | All | All |
| Application | Trendmicro | Password Manager | 5.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Trend Micro Password Manager - Privilege Escalation to SYSTEM | MISC | safebreach.com | Exploit, Third Party Advisory |
| Security Bulletin: Trend Micro Password Manager DLL Hijacking Vulnerabilities · Trend Micro for Home | CONFIRM | esupport.trendmicro.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.