Password Manager TrendMicro Password Manager

Do you want an email whenever new security vulnerabilities are reported in TrendMicro Password Manager?

By the Year

In 2024 there have been 0 vulnerabilities in TrendMicro Password Manager . Password Manager did not have any published security vulnerabilities last year.

Year Vulnerabilities Average Score
2024 0 0.00
2023 0 0.00
2022 3 7.80
2021 1 7.80
2020 3 6.27
2019 3 7.70
2018 0 0.00

It may take a day or so for new Password Manager vulnerabilities to show up in the stats or in the list of recent security vulnerabilties. Additionally vulnerabilities may be tagged under a different product or component name.

Recent TrendMicro Password Manager Security Vulnerabilities

EOL Product CVE - Installer of Trend Micro Password Manager (Consumer) versions 3.7.0.1223 and below provided by Trend Micro Incorporated contains an issue with the DLL search path

CVE-2022-28394 7.8 - High - May 27, 2022

EOL Product CVE - Installer of Trend Micro Password Manager (Consumer) versions 3.7.0.1223 and below provided by Trend Micro Incorporated contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427). Please note that this was reported on an EOL version of the product, and users are advised to upgrade to the latest supported version (5.x).

DLL preloading

Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Privilege Escalation Vulnerability

CVE-2022-30523 7.8 - High - May 16, 2022

Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could allow a low privileged local attacker to delete the contents of an arbitrary folder as SYSTEM which can then be used for privilege escalation on the affected machine.

insecure temporary file

Trend Micro Password Manager (Consumer) installer version 5.0.0.1262 and below is vulnerable to an Uncontrolled Search Path Element vulnerability

CVE-2022-26337 7.8 - High - March 08, 2022

Trend Micro Password Manager (Consumer) installer version 5.0.0.1262 and below is vulnerable to an Uncontrolled Search Path Element vulnerability that could allow an attacker to use a specially crafted file to exploit the vulnerability and escalate local privileges on the affected machine.

DLL preloading

Trend Micro Password Manager version 5 (Consumer) is vulnerable to a DLL Hijacking vulnerability which could

CVE-2021-28647 7.8 - High - April 13, 2021

Trend Micro Password Manager version 5 (Consumer) is vulnerable to a DLL Hijacking vulnerability which could allow an attacker to inject a malicious DLL file during the installation progress and could execute a malicious program each time a user installs a program.

DLL preloading

Trend Micro Password Manager for Windows version 5.0 is affected by a DLL hijacking vulnerability would could potentially

CVE-2020-8469 7.8 - High - March 12, 2020

Trend Micro Password Manager for Windows version 5.0 is affected by a DLL hijacking vulnerability would could potentially allow an attacker privleged escalation.

DLL preloading

A memory usage vulnerability exists in Trend Micro Password Manager 3.8

CVE-2019-15625 5.5 - Medium - January 18, 2020

A memory usage vulnerability exists in Trend Micro Password Manager 3.8 that could allow an attacker with access and permissions to the victim's memory processes to extract sensitive information.

Information Disclosure

A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates

CVE-2019-19696 5.5 - Medium - January 18, 2020

A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to misdirect a user to phishing sites.

Information Disclosure

Trend Micro Password Manager versions 3.x, 5.0, and 5.1 for Android is affected by a FLAG_MISUSE vulnerability

CVE-2019-15629 7.5 - High - November 25, 2019

Trend Micro Password Manager versions 3.x, 5.0, and 5.1 for Android is affected by a FLAG_MISUSE vulnerability that could be exploited to allow the application to share information to third-party applications on the device.

Information Disclosure

A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would

CVE-2019-14684 7.8 - High - August 20, 2019

A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14687.

Untrusted Path

A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would

CVE-2019-14687 7.8 - High - August 20, 2019

A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14684.

Untrusted Path

The HTTP server in Trend Micro Password Manager

CVE-2016-3987 9.8 - Critical - April 12, 2016

The HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDefaultBrowser or (2) api/showSB.

Authorization

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for TrendMicro Password Manager or by TrendMicro? Click the Watch button to subscribe.

TrendMicro
Vendor

subscribe