This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trend Micro Password Manager. Authentication is required to exploit this vulnerability. The specific flaw exists within the Trend Micro Password Manager Central Control Service. The issue results from the exposure of a dangerous method or function to unprivileged users. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro Password Manager |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of ZDI-21-774 is rated as critical due to the potential for remote code execution.
To fix ZDI-21-774, you should update Trend Micro Password Manager to the latest version provided by Trend Micro.
ZDI-21-774 affects installations of Trend Micro Password Manager that have not been updated to address this vulnerability.
Authentication is required to exploit ZDI-21-774, meaning an attacker must have valid credentials.
ZDI-21-774 allows remote attackers to execute arbitrary code on the affected systems.