First published: Fri Jan 17 2020(Updated: )
A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to misdirect a user to phishing sites.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trendmicro Password Manager | >=5.0<=5.0.0.1076 | |
Trendmicro Password Manager | >=5.0<=5.0.1047 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2019-19696 is classified as a medium severity vulnerability.
To mitigate CVE-2019-19696, ensure that you update your Trend Micro Password Manager to the latest version.
CVE-2019-19696 affects Trend Micro Password Manager versions prior to 5.0.0.1076 for Windows and 5.0.1047 for macOS.
CVE-2019-19696 may allow unauthorized access to the localhost.key of RootCA.crt, enabling the creation of malicious self-signed SSL certificates.
Attackers exploiting CVE-2019-19696 could redirect users to phishing sites by creating fraudulent SSL certificates.