CVE-2019-14688

HIGHCVSS 7/10EPSS 1.83%

Last modified

CVE-2019-14688 is a high-severity vulnerability rated 7/10 on the CVSS scale. Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product installation. The vulnerability was found to ONLY be exploitable during an initial product installation by an authorized user. EPSS estimates a 1.83% chance of exploitation in the next 30 days.

Description

Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product installation. The vulnerability was found to ONLY be exploitable during an initial product installation by an authorized user. The attacker must convince the target to download malicious DLL locally which must be present when the installer is run.

Metrics

CVSS 3.1
7/10

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Probability
1.83%

76.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
TrendmicroControl Manager7.0
TrendmicroEndpoint Sensor1.6
TrendmicroIm Security1.6.5
TrendmicroMobile Security9.8
TrendmicroOfficescanxg
TrendmicroScanmail14.0
TrendmicroSecurity2019
TrendmicroServerprotect5.8
TrendmicroServerprotect6.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2019-14688?
Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product installation. The vulnerability was found to ONLY be exploitable during an initial product installation by an authorized user. The attacker must convince the target to download malicious DLL locally which must be present when the installer is run.
How severe is CVE-2019-14688?
CVE-2019-14688 has a CVSS score of 7/10 (HIGH severity). The EPSS model estimates a 1.83% probability of exploitation in the next 30 days.
How do I fix CVE-2019-14688?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-14688?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST