CVE-2022-28394

EOL Product CVE - Installer of Trend Micro Password Manager (Consumer) versions 3.7.0.1223 and below provided by Trend Micro Incorporated contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427). Please note that this was reported on an EOL version of the product, and users are advised to upgrade to the latest supported version (5.x).
References
Configurations

Configuration 1 (hide)

cpe:2.3:a:trendmicro:password_manager:*:*:*:*:*:windows:*:*

History

08 Jun 2022, 16:19

Type Values Removed Values Added
References (N/A) https://helpcenter.trendmicro.com/ja-jp/article/TMKA-10977 - (N/A) https://helpcenter.trendmicro.com/ja-jp/article/TMKA-10977 - Vendor Advisory
References (N/A) https://jvn.jp/jp/JVN60037444/ - (N/A) https://jvn.jp/jp/JVN60037444/ - Third Party Advisory
References (N/A) https://jvn.jp/en/jp/JVN60037444/ - (N/A) https://jvn.jp/en/jp/JVN60037444/ - Third Party Advisory
First Time Trendmicro
Trendmicro password Manager
CPE cpe:2.3:a:trendmicro:password_manager:*:*:*:*:*:windows:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 6.9
v3 : 7.8
CWE CWE-427

02 Jun 2022, 14:15

Type Values Removed Values Added
Summary EOL Product CVE - Installer of Trend Micro Password Manager (Consumer) versions 3.7.0.1223 and below provided by Trend Micro Incorporated contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427). Please note that this was reported on an EOL version of the product, and users are advised to upgrade to the latest supported version (5.x). EOL Product CVE - Installer of Trend Micro Password Manager (Consumer) versions 3.7.0.1223 and below provided by Trend Micro Incorporated contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427). Please note that this was reported on an EOL version of the product, and users are advised to upgrade to the latest supported version (5.x).

27 May 2022, 03:06

Type Values Removed Values Added
New CVE

Information

Published : 2022-05-27 00:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-28394

Mitre link : CVE-2022-28394

CVE.ORG link : CVE-2022-28394


JSON object : View

Products Affected

trendmicro

  • password_manager
CWE
CWE-427

Uncontrolled Search Path Element