7.8

CVE-2019-14686

A DLL hijacking vulnerability exists in the Trend Micro Security's 2019 consumer family of products (v15) Folder Shield component and the standalone Trend Micro Ransom Buster (1.0) tool in which, if exploited, would allow an attacker to load a malicious DLL, leading to elevated privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Antivirus + Security 2019 Version 15.0
   Microsoft ≫ Windows Version -
Trendmicro ≫ Internet Security 2019 Version 15.0
   Microsoft ≫ Windows Version -
Trendmicro ≫ Maximum Security 2019 Version 15.0
   Microsoft ≫ Windows Version -
Trendmicro ≫ Premium Security 2019 Version 15.0
   Microsoft ≫ Windows Version -
Trendmicro ≫ Ransom Buster Version 1.0
   Microsoft ≫ Windows Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.2% 0.642
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-427 Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

https://esupport.trendmicro.com/en-us/home/pages/technical-support/1123421.aspx
Vendor Advisory