7

CVE-2019-14688

Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product installation. The vulnerability was found to ONLY be exploitable during an initial product installation by an authorized user. The attacker must convince the target to download malicious DLL locally which must be present when the installer is run.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Control Manager Version 7.0
   Microsoft ≫ Windows Version -
Trendmicro ≫ Endpoint Sensor Version 1.6
   Microsoft ≫ Windows Version -
Trendmicro ≫ Im Security Version 1.6.5
   Microsoft ≫ Windows Version -
Trendmicro ≫ Mobile Security Version 9.8 SwEdition enterprise
   Microsoft ≫ Windows Version -
Trendmicro ≫ Officescan Version xg
   Microsoft ≫ Windows Version -
Trendmicro ≫ Scanmail Version 14.0 SwPlatform microsoft_exchange
   Microsoft ≫ Windows Version -
Trendmicro ≫ Security Version 2019
   Microsoft ≫ Windows Version -
Trendmicro ≫ Serverprotect Version 5.8 SwPlatform emc
   Microsoft ≫ Windows Version -
Trendmicro ≫ Serverprotect Version 5.8 SwPlatform netware
   Microsoft ≫ Windows Version -
Trendmicro ≫ Serverprotect Version 5.8 SwPlatform windows
   Microsoft ≫ Windows Version -
Trendmicro ≫ Serverprotect Version 6.0 SwPlatform storage
   Microsoft ≫ Windows Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.87% 0.769
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7 1 5.9
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 5.1 4.9 6.4
AV:N/AC:H/Au:N/C:P/I:P/A:P
CWE-427 Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

https://success.trendmicro.com/solution/1123562
Vendor Advisory