cve/2019/CVE-2019-14684.md

19 lines
896 B
Markdown
Raw Normal View History

2024-05-26 14:27:05 +02:00
### [CVE-2019-14684](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2019-14684)
![](https://img.shields.io/static/v1?label=Product&message=Trend%20Micro%20Password%20Manager&color=blue)
![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue)
![](https://img.shields.io/static/v1?label=Vulnerability&message=DLL%20Hijacking&color=brighgreen)
### Description
A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14687.
### POC
#### Reference
- https://safebreach.com/Post/Trend-Micro-Password-Manager-Privilege-Escalation-to-SYSTEM
2024-06-09 00:33:16 +00:00
- https://safebreach.com/Post/Trend-Micro-Password-Manager-Privilege-Escalation-to-SYSTEM
2024-05-26 14:27:05 +02:00
#### Github
No PoCs found on GitHub currently.