Trend Micro Password Manager (Consumer) version 5.0.0.1217 and below is vulnerable to an Exposed Hazardous Function Remote Code Execution vulnerability which could allow an unprivileged client to manipulate the registry and escalate privileges to SYSTEM on affected installations. Authentication is required to exploit this vulnerability.
References
Link | Resource |
---|---|
https://helpcenter.trendmicro.com/en-us/article/TMKA-10388 | Vendor Advisory |
https://www.zerodayinitiative.com/advisories/ZDI-21-774/ | Third Party Advisory VDB Entry |
History
No history.
MITRE Information
Status: PUBLISHED
Assigner: trendmicro
Published: 2021-07-08T10:54:26
Updated: 2021-07-08T10:54:26
Reserved: 2021-05-07T00:00:00
Link: CVE-2021-32462
JSON object: View
NVD Information
Status : Analyzed
Published: 2021-07-08T11:15:12.030
Modified: 2021-07-23T19:58:13.990
Link: CVE-2021-32462
JSON object: View
Redhat Information
No data.
CWE