PT-2025-25263 · Trend Micro · Trend Micro Password Manager

Published

2025-01-14

·

Updated

2025-08-27

·

CVE-2025-48443

CVSS v3.1

6.7

Medium

VectorAV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below
Description The issue allows a local attacker to leverage a Link Following Local Privilege Escalation vulnerability to delete files in the context of an administrator when the administrator installs Trend Micro Password Manager.
Recommendations For Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below, update to a version above 5.0.0.1266 to resolve the issue.

Fix

LPE

Link Following

Weakness Enumeration

Related Identifiers

BDU:2025-08891
CVE-2025-48443
ZDI-25-361

Affected Products

Trend Micro Password Manager