CVE-2019-19696

MEDIUM

Trend Micro Password Manager - Info Disclosure

Title source: llm

Description

A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to misdirect a user to phishing sites.

Scores

CVSS v3 5.5
EPSS 0.0013
EPSS Percentile 32.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Classification

CWE
CWE-522
Status published

Affected Products (2)

trendmicro/password_manager < 5.0.0.1076
trendmicro/password_manager < 5.0.1047

Timeline

Published Jan 18, 2020
Tracked Since Feb 18, 2026