PT-2021-19714 · Trend Micro · Trend Micro Password Manager

Simon Zuckerbraun

·

Published

2021-07-05

·

Updated

2021-07-23

·

CVE-2021-32462

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Trend Micro Password Manager (Consumer) version 5.0.0.1217 and below
Description: The issue allows an unprivileged client to manipulate the registry and escalate privileges to SYSTEM on affected installations through an Exposed Hazardous Function Remote Code Execution. Authentication is required to exploit this issue.
Recommendations: For versions 5.0.0.1217 and below, at the moment, there is no information about a newer version that contains a fix for this issue.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-32462
ZDI-21-774

Affected Products

Trend Micro Password Manager