CVE-2019-14687

HIGH

Trend Micro Password Manager 5.0 - DLL Hijacking

Title source: llm
STIX 2.1

Description

A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14684.

References (2)

Core 2
Core References
Various Sources x_refsource_misc
https://medium.com/%40infiniti_css/fa839acaad59

Scores

CVSS v3 7.8
EPSS 0.0030
EPSS Percentile 53.6%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-427
Status published
Products (1)
trendmicro/password_manager 5.0
Published Aug 20, 2019
Tracked Since Feb 18, 2026