{"api_version":"1","generated_at":"2026-07-23T13:16:44+00:00","cve":"CVE-2019-14684","urls":{"html":"https://cve.report/CVE-2019-14684","api":"https://cve.report/api/cve/CVE-2019-14684.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2019-14684","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2019-14684"},"summary":{"title":"CVE-2019-14684","description":"A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14687.","state":"PUBLIC","assigner":"security@trendmicro.com","published_at":"2019-08-20 14:15:00","updated_at":"2021-07-21 11:39:00"},"problem_types":["CWE-427"],"metrics":[],"references":[{"url":"https://safebreach.com/Post/Trend-Micro-Password-Manager-Privilege-Escalation-to-SYSTEM","name":"https://safebreach.com/Post/Trend-Micro-Password-Manager-Privilege-Escalation-to-SYSTEM","refsource":"MISC","tags":["Exploit","Third Party Advisory"],"title":"Trend Micro Password Manager - Privilege Escalation to SYSTEM","mime":"text/html","httpstatus":"404","archivestatus":"200"},{"url":"https://esupport.trendmicro.com/en-us/home/pages/technical-support/1123396.aspx","name":"https://esupport.trendmicro.com/en-us/home/pages/technical-support/1123396.aspx","refsource":"CONFIRM","tags":["Vendor Advisory"],"title":"Security Bulletin: Trend Micro Password Manager DLL Hijacking Vulnerabilities · Trend Micro for Home","mime":"text/html","httpstatus":"200","archivestatus":"0"},{"url":"https://www.cve.org/CVERecord?id=CVE-2019-14684","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2019-14684","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2019","cve_id":"14684","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"trendmicro","cpe5":"password_manager","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2019","cve_id":"14684","vulnerable":"1","versionEndIncluding":"1","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"trendmicro","cpe5":"password_manager","cpe6":"5.0","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@trendmicro.com","ID":"CVE-2019-14684","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Trend Micro Password Manager","version":{"version_data":[{"version_value":"2019 (5.0)"}]}}]},"vendor_name":"Trend Micro"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14687."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"DLL Hijacking"}]}]},"references":{"reference_data":[{"url":"https://safebreach.com/Post/Trend-Micro-Password-Manager-Privilege-Escalation-to-SYSTEM","refsource":"MISC","name":"https://safebreach.com/Post/Trend-Micro-Password-Manager-Privilege-Escalation-to-SYSTEM"},{"refsource":"CONFIRM","name":"https://esupport.trendmicro.com/en-us/home/pages/technical-support/1123396.aspx","url":"https://esupport.trendmicro.com/en-us/home/pages/technical-support/1123396.aspx"}]}},"nvd":{"publishedDate":"2019-08-20 14:15:00","lastModifiedDate":"2021-07-21 11:39:00","problem_types":["CWE-427"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.0","vectorString":"CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:M/Au:N/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":9.3},"severity":"HIGH","exploitabilityScore":8.6,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:trendmicro:password_manager:5.0:*:*:*:*:*:*:*","cpe_name":[]}]}]}},"legacy_mitre":{"record":{"CveYear":"2019","CveId":"14684","Ordinal":"153889","Title":"CVE-2019-14684","CVE":"CVE-2019-14684","Year":"2019"},"notes":[{"CveYear":"2019","CveId":"14684","Ordinal":"1","NoteData":"A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14687.","Type":"Description","Title":null},{"CveYear":"2019","CveId":"14684","Ordinal":"2","NoteData":"2019-08-20","Type":"Other","Title":"Published"},{"CveYear":"2019","CveId":"14684","Ordinal":"3","NoteData":"2019-08-20","Type":"Other","Title":"Modified"}]}}}