← Vulnerability feed

Vulnerability record · CVE-2022-28394 · published 27 May 2022

CVE-2022-28394: Trendmicro password manager uncontrolled search path element vulnerability

Trendmicro · Password Manager

EOL Product CVE - Installer of Trend Micro Password Manager (Consumer) versions 3.7.0.1223 and below provided by Trend Micro Incorporated contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427). Please note that this was reported on an EOL version of the product, and users are advised to upgrade to the latest supported version (5.x).

7.8 CVSS 3.1 High EPSS 0.27% · top 82.3% CWE-427 · Uncontrolled search path element
7.8CVSS 3.1 base score, v2 6.9
0.27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

EOL Product CVE - Installer of Trend Micro Password Manager (Consumer) versions 3.7.0.1223 and below provided by Trend Micro Incorporated contains an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries (CWE-427). Please note that this was reported on an EOL version of the product, and users are advised to upgrade to the latest supported version (5.x).

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2022-28394 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2016-3987Trendmicro password manager improper access control vulnerabilityThe HTTP server in Trend Micro Password Manager allows remote web servers to execute arbitrary commands via the url parameter to (1) api/openUrlInDef…EPSS 22%8.8CVE-2021-32462Trendmicro password manager vulnerabilityTrend Micro Password Manager (Consumer) version 5.0.0.1217 and below is vulnerable to an Exposed Hazardous Function Remote Code Execution vulnerabili…EPSS 5.2%7.8CVE-2025-52837Trendmicro password manager link following vulnerabilityTrend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could …EPSS 0.16%7.8CVE-2022-30523Trendmicro password manager link following vulnerabilityTrend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Privilege Escalation Vulnerability that could …EPSS 0.40%7.8CVE-2022-26337Trendmicro password manager uncontrolled search path element vulnerabilityTrend Micro Password Manager (Consumer) installer version 5.0.0.1262 and below is vulnerable to an Uncontrolled Search Path Element vulnerability tha…EPSS 0.68%7.8CVE-2021-32461Trendmicro password manager vulnerabilityTrend Micro Password Manager (Consumer) version 5.0.0.1217 and below is vulnerable to an Integer Truncation Privilege Escalation vulnerability which …EPSS 0.37%7.8CVE-2021-28647Trendmicro password manager uncontrolled search path element vulnerabilityTrend Micro Password Manager version 5 (Consumer) is vulnerable to a DLL Hijacking vulnerability which could allow an attacker to inject a malicious …EPSS 0.47%7.8CVE-2020-8469Trendmicro password manager uncontrolled search path element vulnerabilityTrend Micro Password Manager for Windows version 5.0 is affected by a DLL hijacking vulnerability would could potentially allow an attacker privleged…EPSS 0.46%

Source: NIST National Vulnerability Database (record CVE-2022-28394), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.