Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-26337

Опубликовано: 08 мар. 2022
Источник: nvd
CVSS3: 7.8
CVSS2: 9.3
EPSS Низкий

Описание

Trend Micro Password Manager (Consumer) installer version 5.0.0.1262 and below is vulnerable to an Uncontrolled Search Path Element vulnerability that could allow an attacker to use a specially crafted file to exploit the vulnerability and escalate local privileges on the affected machine.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:trendmicro:password_manager:*:*:*:*:*:windows:*:*
Версия до 5.0.0.1266 (исключая)

EPSS

Процентиль: 46%
0.0023
Низкий

7.8 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-427

Связанные уязвимости

CVSS3: 7.8
github
почти 4 года назад

Trend Micro Password Manager (Consumer) installer version 5.0.0.1262 and below is vulnerable to an Uncontrolled Search Path Element vulnerability that could allow an attacker to use a specially crafted file to exploit the vulnerability and escalate local privileges on the affected machine.

EPSS

Процентиль: 46%
0.0023
Низкий

7.8 High

CVSS3

9.3 Critical

CVSS2

Дефекты

CWE-427