cve/2019/CVE-2019-14684.md

18 lines
805 B
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2019-14684](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14684)
![](https://img.shields.io/static/v1?label=Product&message=Trend%20Micro%20Password%20Manager&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=DLL%20Hijacking&color=brighgreen)
### Description
A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14687.
### POC
#### Reference
- https://safebreach.com/Post/Trend-Micro-Password-Manager-Privilege-Escalation-to-SYSTEM
#### Github
No PoCs found on GitHub currently.