CVE-2025-48443

MEDIUM

Trend Micro Password Manager <5.0.0.1266 - Privilege Escalation

Title source: llm
STIX 2.1

Description

Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Local Privilege Escalation Vulnerability that could allow a local attacker to leverage this vulnerability to delete files in the context of an administrator when the administrator installs Trend Micro Password Manager.

References (2)

Core 2

Scores

CVSS v3 6.7
EPSS 0.0008
EPSS Percentile 22.8%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-64
Status published
Products (1)
trendmicro/password_manager < 5.8.0.1330
Published Jun 17, 2025
Tracked Since Feb 18, 2026