A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to misdirect a user to phishing sites.
References
Link | Resource |
---|---|
https://esupport.trendmicro.com/en-us/home/pages/technical-support/1124092.aspx | Vendor Advisory |
https://esupport.trendmicro.com/support/pwm/solution/ja-jp/1124091.aspx | Vendor Advisory |
https://jvn.jp/en/jp/JVN37183636/index.html | Third Party Advisory |
https://jvn.jp/jp/JVN37183636/index.html | Third Party Advisory |
https://esupport.trendmicro.com/en-us/home/pages/technical-support/1124092.aspx | Vendor Advisory |
https://esupport.trendmicro.com/support/pwm/solution/ja-jp/1124091.aspx | Vendor Advisory |
https://jvn.jp/en/jp/JVN37183636/index.html | Third Party Advisory |
https://jvn.jp/jp/JVN37183636/index.html | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
21 Nov 2024, 04:35
Type | Values Removed | Values Added |
---|---|---|
References | () https://esupport.trendmicro.com/en-us/home/pages/technical-support/1124092.aspx - Vendor Advisory | |
References | () https://esupport.trendmicro.com/support/pwm/solution/ja-jp/1124091.aspx - Vendor Advisory | |
References | () https://jvn.jp/en/jp/JVN37183636/index.html - Third Party Advisory | |
References | () https://jvn.jp/jp/JVN37183636/index.html - Third Party Advisory |
Information
Published : 2020-01-18 00:15
Updated : 2024-11-21 04:35
NVD link : CVE-2019-19696
Mitre link : CVE-2019-19696
CVE.ORG link : CVE-2019-19696
JSON object : View
Products Affected
trendmicro
- password_manager
CWE
CWE-522
Insufficiently Protected Credentials