CVE-2022-28394
Summary
| CVE | CVE-2022-28394 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-05-27 00:15:00 UTC |
| Updated | 2022-06-08 16:19:00 UTC |
| Description | EOL Product CVE - Installer of Trend Micro Password Manager (Consumer) versions 3.7.0.1223 and below provided by Trend Micro Incorporated contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427). Please note that this was reported on an EOL version of the product, and users are advised to upgrade to the latest supported version (5.x). |
Risk And Classification
Problem Types: CWE-427
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Trendmicro | Password Manager | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| アラート/アドバイザリ:パスワードマネージャーの脆弱性について (CVE-2022-28394) · Trend Micro for Home | N/A | helpcenter.trendmicro.com | |
| JVN#60037444: Installer of Trend Micro Password Manager may insecurely load Dynamic Link Libraries | N/A | jvn.jp | |
| JVN#60037444: トレンドマイクロ製パスワードマネージャーのインストーラにおける DLL 読み込みに関する脆弱性 | N/A | jvn.jp | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.