PoC Index

CVE-2019-14684

HIGH 9.3EPSS 1.5%

A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14687.

CVSS v3.0
7.8 HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v2.0
9.3 HIGHAV:N/AC:M/Au:N/C:C/I:C/A:C
EPSS
1.46% chance of exploitation in the next 30 days, 72th percentile
Published
2019-08-20
Updated
2024-08-05

Proof-of-concept exploits (1)

References

Related