{"api_version":"1","generated_at":"2026-07-23T20:19:25+00:00","cve":"CVE-2022-28394","urls":{"html":"https://cve.report/CVE-2022-28394","api":"https://cve.report/api/cve/CVE-2022-28394.json","docs":"https://cve.report/api","cve_org":"https://www.cve.org/CVERecord?id=CVE-2022-28394","nvd":"https://nvd.nist.gov/vuln/detail/CVE-2022-28394"},"summary":{"title":"CVE-2022-28394","description":"EOL Product CVE - Installer of Trend Micro Password Manager (Consumer) versions 3.7.0.1223 and below provided by Trend Micro Incorporated contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427). Please note that this was reported on an EOL version of the product, and users are advised to upgrade to the latest supported version (5.x).","state":"PUBLIC","assigner":"security@trendmicro.com","published_at":"2022-05-27 00:15:00","updated_at":"2022-06-08 16:19:00"},"problem_types":["CWE-427"],"metrics":[],"references":[{"url":"https://helpcenter.trendmicro.com/ja-jp/article/TMKA-10977","name":"N/A","refsource":"N/A","tags":[],"title":"アラート/アドバイザリ：パスワードマネージャーの脆弱性について (CVE-2022-28394)\r\n\t\t · Trend Micro for Home","mime":"text/html","httpstatus":"200","archivestatus":"404"},{"url":"https://jvn.jp/en/jp/JVN60037444/","name":"N/A","refsource":"N/A","tags":[],"title":"JVN#60037444: Installer of Trend Micro Password Manager may insecurely load Dynamic Link Libraries","mime":"text/xml","httpstatus":"200","archivestatus":"404"},{"url":"https://jvn.jp/jp/JVN60037444/","name":"N/A","refsource":"N/A","tags":[],"title":"JVN#60037444: トレンドマイクロ製パスワードマネージャーのインストーラにおける DLL 読み込みに関する脆弱性","mime":"text/xml","httpstatus":"200","archivestatus":"200"},{"url":"https://www.cve.org/CVERecord?id=CVE-2022-28394","name":"CVE Program record","refsource":"CVE.ORG","tags":["canonical"]},{"url":"https://nvd.nist.gov/vuln/detail/CVE-2022-28394","name":"NVD vulnerability detail","refsource":"NVD","tags":["canonical","analysis"]}],"affected":[],"timeline":[],"solutions":[],"workarounds":[],"exploits":[],"credits":[],"nvd_cpes":[{"cve_year":"2022","cve_id":"28394","vulnerable":"1","versionEndIncluding":"","cpe1":"cpe","cpe2":"2.3","cpe3":"a","cpe4":"trendmicro","cpe5":"password_manager","cpe6":"*","cpe7":"*","cpe8":"*","cpe9":"*","cpe10":"*","cpe11":"windows","cpe12":"*","cpe13":"*"}],"vendor_comments":[],"enrichments":{"kev":null,"epss":null,"legacy_qids":[]},"source_records":{"cve_program":{"CVE_data_meta":{"ASSIGNER":"security@trendmicro.com","ID":"CVE-2022-28394","STATE":"PUBLIC"},"affects":{"vendor":{"vendor_data":[{"product":{"product_data":[{"product_name":"Trend Micro Password Manager","version":{"version_data":[{"version_value":"3.7.0.1223 and below"}]}}]},"vendor_name":"Trend Micro"}]}},"data_format":"MITRE","data_type":"CVE","data_version":"4.0","description":{"description_data":[{"lang":"eng","value":"EOL Product CVE - Installer of Trend Micro Password Manager (Consumer) versions 3.7.0.1223 and below provided by Trend Micro Incorporated contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427). Please note that this was reported on an EOL version of the product, and users are advised to upgrade to the latest supported version (5.x)."}]},"problemtype":{"problemtype_data":[{"description":[{"lang":"eng","value":"Uncontrolled Search Path Element"}]}]},"references":{"reference_data":[{"url":"https://helpcenter.trendmicro.com/ja-jp/article/TMKA-10977","refsource":"MISC","name":"https://helpcenter.trendmicro.com/ja-jp/article/TMKA-10977"},{"url":"https://jvn.jp/en/jp/JVN60037444/","refsource":"MISC","name":"https://jvn.jp/en/jp/JVN60037444/"},{"url":"https://jvn.jp/jp/JVN60037444/","refsource":"MISC","name":"https://jvn.jp/jp/JVN60037444/"}]}},"nvd":{"publishedDate":"2022-05-27 00:15:00","lastModifiedDate":"2022-06-08 16:19:00","problem_types":["CWE-427"],"metrics":{"baseMetricV3":{"cvssV3":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9},"baseMetricV2":{"cvssV2":{"version":"2.0","vectorString":"AV:L/AC:M/Au:N/C:C/I:C/A:C","accessVector":"LOCAL","accessComplexity":"MEDIUM","authentication":"NONE","confidentialityImpact":"COMPLETE","integrityImpact":"COMPLETE","availabilityImpact":"COMPLETE","baseScore":6.9},"severity":"MEDIUM","exploitabilityScore":3.4,"impactScore":10,"acInsufInfo":false,"obtainAllPrivilege":false,"obtainUserPrivilege":false,"obtainOtherPrivilege":false,"userInteractionRequired":true}},"configurations":{"CVE_data_version":"4.0","nodes":[{"operator":"OR","children":[],"cpe_match":[{"vulnerable":true,"cpe23Uri":"cpe:2.3:a:trendmicro:password_manager:*:*:*:*:*:windows:*:*","versionEndExcluding":"3.7.0.1223","cpe_name":[]}]}]}},"legacy_mitre":{"record":null,"notes":[]}}}