QID 377987
Date Published: 2023-02-16
QID 377987: Trend Micro Password Manager Link Following Privilege Escalation Vulnerability
Trend Micro Password Manager handles all the basics. It captures passwords as you log in, plays them back when needed, and offers a browser menu of all your saved logins. It keeps secure notes for you, and helps you fill Web forms. It even offers a secure browser for your financial sites.
Affected Versions:
Trend Micro Password Manager 5.0.0.1266 and below
QID detection logic: (Authenticated)
It check the vulnerable version by checking the registry keys.
Successful exploitation could allow a low-privileged local attacker to delete the contents of an arbitrary folder as "SYSTEM," which can then be used for privilege escalation on the affected machine.
Solution
Vendor References
- tmka-09071 -
helpcenter.trendmicro.com/en-us/article/tmka-09071
CVEs related to QID 377987
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| tmka-09071 |
|