← Vulnerability feed

Vulnerability record · CVE-2019-14686 · published 21 August 2019

CVE-2019-14686: Trendmicro antivirus \+ security 2019 uncontrolled search path element vulnerability

Trendmicro · Antivirus \+ Security 2019

A DLL hijacking vulnerability exists in the Trend Micro Security's 2019 consumer family of products (v15) Folder Shield component and the standalone Trend Micro Ransom Buster (1.0) tool in which, if exploited, would allow an attacker to load a malicious DLL, leading to elevated privileges.

7.8 CVSS 3.0 High EPSS 1.2% · top 32.9% CWE-427 · Uncontrolled search path element
7.8CVSS 3.0 base score, v2 6.8
1.2%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

A DLL hijacking vulnerability exists in the Trend Micro Security's 2019 consumer family of products (v15) Folder Shield component and the standalone Trend Micro Ransom Buster (1.0) tool in which, if exploited, would allow an attacker to load a malicious DLL, leading to elevated privileges.

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-14686 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2021-36744Trendmicro maximum security 2019 link following vulnerabilityTrend Micro Security (Consumer) 2021 and 2020 are vulnerable to a directory junction vulnerability which could allow an attacker to exploit the syste…EPSS 0.47%7.8CVE-2019-20357Trendmicro antivirus \+ security 2019 unquoted search path vulnerabilityA Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which c…EPSS 0.73%7.8CVE-2019-14685Trendmicro antivirus \+ security 2019 unquoted search path vulnerabilityA local privilege escalation vulnerability exists in Trend Micro Security 2019 (v15.0) in which, if exploited, would allow an attacker to manipulate …EPSS 0.59%7.5CVE-2020-15604Trendmicro antivirus\+ 2019 improper certificate validation vulnerabilityAn incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an att…EPSS 1.6%7.5CVE-2020-24560Trendmicro antivirus\+ 2019 improper certificate validation vulnerabilityAn incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an att…EPSS 1.8%6.7CVE-2019-19697Trendmicro antivirus \+ security 2019 vulnerabilityAn arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products which could allow an attacker to …EPSS 0.82%4.7CVE-2019-19694Trendmicro antivirus \+ security 2019 vulnerabilityThe Trend Micro Security 2019 (15.0.0.1163 and below) consumer family of products is vulnerable to a denial of service (DoS) attack in which a malici…EPSS 0.37%7.8CVE-2020-3433Cisco AnyConnect Windows client DLL hijacking via IPC channelCisco AnyConnect Secure Mobility Client for Windows fails to properly validate resources loaded at run time, allowing a DLL hijacking attack through …KEVEPSS 10%analysed

Source: NIST National Vulnerability Database (record CVE-2019-14686), CISA KEV, FIRST EPSS (scores of 2026-10-01). This page is refreshed as NVD updates the record.