CVE-2019-14688
Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product installation. The vulnerability was found to ONLY be exploitable during an initial product installation by an authorized user. The attacker must convince the target to download malicious DLL locally which must be present when the installer is run.
Published:Feb 20, 2020
Last Modified:Nov 21, 2024
EPS:Feb 20, 2020
EPSS Score:0.00409
CVSS Score:7
Affected Products
Vendor
Product
Action
Vendor
Microsoft
Product
Windows
Microsoft
Windows
Vendor
Trendmicro
Product
Control Manager
Trendmicro
Control Manager
Vendor
Trendmicro
Product
Endpoint Sensor
Trendmicro
Endpoint Sensor
Vendor
Trendmicro
Product
Im Security
Trendmicro
Im Security
Vendor
Trendmicro
Product
Mobile Security
Trendmicro
Mobile Security
Vendor
Trendmicro
Product
Officescan
Trendmicro
Officescan
Vendor
Trendmicro
Product
Scanmail
Trendmicro
Scanmail
Vendor
Trendmicro
Product
Security
Trendmicro
Security
Vendor
Trendmicro
Product
Serverprotect
Trendmicro
Serverprotect
Exploits
No exploit reference
Common Weakness Enumeration
Common Attack Pattern Enumeration and Classification (CAPEC)
Related CVEs
Common Vulnerability Scoring System
Attack Vector
Network
Adjacent
Local
Physical
Privileges Required
None
Low
High
User Interaction
None
Required
Scope
Unchanged
Changed
Confidentiality
None
Low
High
Integrity
None
Low
High
Availability
None
Low
High
