Vulnerabilities > Trendmicro > Password Manager > 5.0.0.1076

DATE CVE VULNERABILITY TITLE RISK
2022-05-16 CVE-2022-30523 Link Following vulnerability in Trendmicro Password Manager
Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could allow a low privileged local attacker to delete the contents of an arbitrary folder as SYSTEM which can then be used for privilege escalation on the affected machine.
local
low complexity
trendmicro CWE-59
7.2
2022-03-08 CVE-2022-26337 Uncontrolled Search Path Element vulnerability in Trendmicro Password Manager
Trend Micro Password Manager (Consumer) installer version 5.0.0.1262 and below is vulnerable to an Uncontrolled Search Path Element vulnerability that could allow an attacker to use a specially crafted file to exploit the vulnerability and escalate local privileges on the affected machine.
network
trendmicro CWE-427
critical
9.3
2021-07-08 CVE-2021-32461 Incorrect Conversion between Numeric Types vulnerability in Trendmicro Password Manager
Trend Micro Password Manager (Consumer) version 5.0.0.1217 and below is vulnerable to an Integer Truncation Privilege Escalation vulnerability which could allow a local attacker to trigger a buffer overflow and escalate privileges on affected installations.
local
low complexity
trendmicro CWE-681
7.2
2021-07-08 CVE-2021-32462 Unspecified vulnerability in Trendmicro Password Manager
Trend Micro Password Manager (Consumer) version 5.0.0.1217 and below is vulnerable to an Exposed Hazardous Function Remote Code Execution vulnerability which could allow an unprivileged client to manipulate the registry and escalate privileges to SYSTEM on affected installations.
network
low complexity
trendmicro
critical
9.0
2021-04-13 CVE-2021-28647 Uncontrolled Search Path Element vulnerability in Trendmicro Password Manager 5.0/5.0.0.1076/5.0.0.1081
Trend Micro Password Manager version 5 (Consumer) is vulnerable to a DLL Hijacking vulnerability which could allow an attacker to inject a malicious DLL file during the installation progress and could execute a malicious program each time a user installs a program.
4.4
2020-01-18 CVE-2019-19696 Information Exposure vulnerability in Trendmicro Password Manager
A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to misdirect a user to phishing sites.
local
low complexity
trendmicro CWE-200
2.1