← Vulnerability feed

Vulnerability record · CVE-2019-19696 · published 18 January 2020

CVE-2019-19696: Trendmicro password manager insufficiently protected credentials vulnerability

Trendmicro · Password Manager

A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to misdirect a user to phishing sites.

5.5 CVSS 3.1 Medium EPSS 0.47% · top 61.6% CWE-522 · Insufficiently protected credentials
5.5CVSS 3.1 base score, v2 2.1
0.47%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
8References
17 Jun 2026Last modified by NVD

Description

A RootCA vulnerability found in Trend Micro Password Manager for Windows and macOS exists where the localhost.key of RootCA.crt might be improperly accessed by an unauthorized party and could be used to create malicious self-signed SSL certificates, allowing an attacker to misdirect a user to phishing sites.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2019-19696 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-3987Trendmicro password manager improper access control vulnerabilityThe HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDef…EPSS 22%8.8CVE-2021-32462Trendmicro password manager vulnerabilityTrend Micro Password Manager (Consumer) version 5.0.0.1217 and below is vulnerable to an Exposed Hazardous Function Remote Code Execution vulnerabili…EPSS 5.2%7.8CVE-2025-52837Trendmicro password manager link following vulnerabilityTrend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could …EPSS 0.16%7.8CVE-2022-28394Trendmicro password manager uncontrolled search path element vulnerabilityEOL Product CVE - Installer of Trend Micro Password Manager (Consumer) versions 3.7.0.1223 and below provided by Trend Micro Incorporated contains an…EPSS 0.27%7.8CVE-2022-30523Trendmicro password manager link following vulnerabilityTrend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could …EPSS 0.40%7.8CVE-2022-26337Trendmicro password manager uncontrolled search path element vulnerabilityTrend Micro Password Manager (Consumer) installer version 5.0.0.1262 and below is vulnerable to an Uncontrolled Search Path Element vulnerability tha…EPSS 0.68%7.8CVE-2021-32461Trendmicro password manager vulnerabilityTrend Micro Password Manager (Consumer) version 5.0.0.1217 and below is vulnerable to an Integer Truncation Privilege Escalation vulnerability which …EPSS 0.37%7.8CVE-2021-28647Trendmicro password manager uncontrolled search path element vulnerabilityTrend Micro Password Manager version 5 (Consumer) is vulnerable to a DLL Hijacking vulnerability which could allow an attacker to inject a malicious …EPSS 0.47%

Source: NIST National Vulnerability Database (record CVE-2019-19696), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.