CVE-2019-14686
Summary
| CVE | CVE-2019-14686 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2019-08-21 20:15:00 UTC |
| Updated | 2021-07-21 11:39:00 UTC |
| Description | A DLL hijacking vulnerability exists in the Trend Micro Security's 2019 consumer family of products (v15) Folder Shield component and the standalone Trend Micro Ransom Buster (1.0) tool in which, if exploited, would allow an attacker to load a malicious DLL, leading to elevated privileges. |
Risk And Classification
Problem Types: CWE-427
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Microsoft | Windows | - | All | All | All |
| Operating System | Microsoft | Windows | - | All | All | All |
| Application | Trendmicro | Antivirus Security 2019 | 15.0 | All | All | All |
| Application | Trendmicro | Antivirus Security 2019 | 15.0 | All | All | All |
| Application | Trendmicro | Antivirus Security 2019 | 15.0 | All | All | All |
| Application | Trendmicro | Internet Security 2019 | 15.0 | All | All | All |
| Application | Trendmicro | Internet Security 2019 | 15.0 | All | All | All |
| Application | Trendmicro | Maximum Security 2019 | 15.0 | All | All | All |
| Application | Trendmicro | Maximum Security 2019 | 15.0 | All | All | All |
| Application | Trendmicro | Premium Security 2019 | 15.0 | All | All | All |
| Application | Trendmicro | Premium Security 2019 | 15.0 | All | All | All |
| Application | Trendmicro | Ransom Buster | 1.0 | All | All | All |
| Application | Trendmicro | Ransom Buster | 1.0 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Security Bulletin: Trend Micro Ransom Buster and Trend Micro Security 2019 (Consumer) Folder Shield DLL Hijack Vulnerability · Trend Micro for Home | CONFIRM | esupport.trendmicro.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.