CVE-2019-14684

HIGH

Trend Micro Password Manager 5.0 - DLL Hijacking

Title source: llm
STIX 2.1

Description

A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14687.

References (2)

Core 2

Scores

CVSS v3 7.8
EPSS 0.0039
EPSS Percentile 60.5%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-427
Status published
Products (1)
trendmicro/password_manager 5.0
Published Aug 20, 2019
Tracked Since Feb 18, 2026