{"api_version":"1","generated_at":"2026-07-24T00:34:09+00:00","cve":"CVE-2021-32462","urls":{"html":"https://cve.report/CVE-2021-32462","api":"https://cve.report/api/cve/CVE-2021-32462.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2021-32462","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2021-32462"},"summary":{"title":"CVE-2021-32462","description":"Trend Micro Password Manager (Consumer) version 5.0.0.1217 and below is vulnerable to an Exposed Hazardous Function Remote Code Execution vulnerability which could allow an unprivileged client to manipulate the registry and escalate privileges to SYSTEM on affected installations. Authentication is required to exploit this vulnerability.","state":"PUBLIC","assigner":"security@trendmicro.com","published_at":"2021-07-08 11:15:00","updated_at":"2021-07-23 19:58:00"},"problem_types":["NVD-CWE-Other"],"metrics":[],"references":[{"url":"https://helpcenter.trendmicro.com/en-us/article/TMKA-10388","name":"https://helpcenter.trendmicro.com/en-us/article/TMKA-10388","refsource":"MISC","tags":[],"title":"Security Bulletin: June 2021 Security Bulletin for Trend Micro Password Manager\r\n\t\t · Trend Micro for Home","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-21-774/","name":"https://www.zerodayinitiative.com/advisories/ZDI-21-774/","refsource":"MISC","tags":[],"title":"ZDI-21-774 | Zero Day Initiative","mime":"text/html","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2021-32462","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2021-32462","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2021","cve_id":"32462","vulnerable":"-1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"o","cpe4":"microsoft","cpe5":"windows","cpe6":"-","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"},{"cve_year":"2021","cve_id":"32462","vulnerable":"1","versionEndIncluding":"5.0.0.1217","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"trendmicro","cpe5":"password_manager","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"*","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@trendmicro.com","ID":"CVE-2021-32462","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Trend Micro Password Manager","version":{"version_data":[{"version_value":"5.0.0.1217 and below"}]}}]},"vendor_name":"Trend Micro"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"Trend Micro Password Manager (Consumer) version 5.0.0.1217 and below is vulnerable to an Exposed Hazardous Function Remote Code Execution vulnerability which could allow an unprivileged client to manipulate the registry and escalate privileges to SYSTEM on affected installations. Authentication is required to exploit this vulnerability."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Exposed Hazardous Function RCE"}]}]},"references":{"reference_data":[{"url":"https://helpcenter.trendmicro.com/en-us/article/TMKA-10388","refsource":"MISC","name":"https://helpcenter.trendmicro.com/en-us/article/TMKA-10388"},{"url":"https://www.zerodayinitiative.com/advisories/ZDI-21-774/","refsource":"MISC","name":"https://www.zerodayinitiative.com/advisories/ZDI-21-774/"}]}},"nvd":{"publishedDate":"2021-07-08 11:15:00","lastModifiedDate":"2021-07-23 19:58:00","problem_types":["NVD-CWE-Other"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","attackVector":"NETWORK","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":8.8,"baseSeverity":"HIGH"},"exploitabilityScore":2.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:N/AC:L/Au:S/C:C/I:C/A:C","accessVector":"NETWORK","accessComplexity":"LOW","authentication":"SINGLE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":9},"severity":"HIGH","exploitabilityScore":8,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":false}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"AND","children":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:trendmicro:password_manager:*:*:*:*:*:*:*:*","versionEndIncluding":"5.0.0.1217","cpe_name":[]}]},{"operator":"OR","children":[],"cpe_match":[{"vulnerable":false,"cpe23Uri":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","cpe_name":[]}]}],"cpe_match":[]}]}},"legacy_mitre":{"record":{"CveYear":"2021","CveId":"32462","Ordinal":"207841","Title":"CVE-2021-32462","CVE":"CVE-2021-32462","Year":"2021"},"notes":[{"CveYear":"2021","CveId":"32462","Ordinal":"1","NoteData":"Trend Micro Password Manager (Consumer) version 5.0.0.1217 and below is vulnerable to an Exposed Hazardous Function Remote Code Execution vulnerability which could allow an unprivileged client to manipulate the registry and escalate privileges to SYSTEM on affected installations. Authentication is required to exploit this vulnerability.","Type":"Description","Title":null},{"CveYear":"2021","CveId":"32462","Ordinal":"2","NoteData":"2021-07-08","Type":"Other","Title":"Published"},{"CveYear":"2021","CveId":"32462","Ordinal":"3","NoteData":"2021-07-08","Type":"Other","Title":"Modified"}]}}}