CVE-2021-32462: Trend Micro Password Manager Remote Code Execution Vulnerability
Vulnerability Detail
CVE-2021-32461: Integer Truncation Privilege Escalation
CVSSv3: 7.0: AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
Trend Micro Password Manager (Consumer) version 5.0.0.1217 and below is vulnerable to an Integer Truncation Privilege Escalation vulnerability which could allow an unprivileged local attacker to trigger a buffer overflow and escalate privileges on affected installations.
CVE-2021-32462: Exposed Hazardous Function Remote Code Execution
CVSSv3: 8.8: AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Trend Micro Password Manager (Consumer) version 5.0.0.1217 and below is vulnerable to an Exposed Hazardous Function Remote Code Execution vulnerability which could allow an unprivileged client to manipulate the registry and escalate privileges to SYSTEM on affected installations.
Trend Micro has received no reports nor is aware of any actual attacks against the affected product related to this vulnerability at this time.