CVE-2025-52837
7.8Trend Micro · Password Manager (Consumer)
Trend Micro Password Manager version 5.8.0.1327 and below is susceptible to a privilege escalation flaw allowing unauthorized file or folder deletion via symbolic link abuse.
Executive summary
A critical privilege escalation vulnerability in Trend Micro Password Manager allows a local attacker to delete arbitrary files and potentially gain elevated system access.
Vulnerability
The application is vulnerable to a Link Following Privilege Escalation issue (CWE-64). A local attacker with low privileges can manipulate symbolic links to trick the application into deleting arbitrary files or folders, which can be leveraged to achieve privilege escalation.
Business impact
The ability for a local user to delete arbitrary files on the system presents a severe risk to system integrity and stability. By targeting sensitive configuration or system files, an attacker could escalate privileges to gain full control over the host, leading to total compromise of stored credentials and sensitive data. With a CVSS score of 7.8, this vulnerability is categorized as High severity, necessitating prompt remediation to prevent local system exploitation.
Remediation
Immediate Action: Update Trend Micro Password Manager to version 5.8.0.1327 or later as provided in the official vendor advisory (TMKA-12946).
Proactive Monitoring: Monitor system logs for unusual file deletion events or unauthorized attempts to create symbolic links in directories associated with the application.
Compensating Controls: Ensure that standard users have the minimum necessary filesystem permissions and avoid running non-essential applications with administrative privileges.
Exploitation status
Public Exploit Available: No — there is no evidence of a weaponized exploit or public proof-of-concept in the provided data.
Analyst recommendation
Given the potential for privilege escalation and arbitrary file deletion, it is imperative that organizations deploy the vendor-supplied update immediately. Administrators should verify that all installations of Trend Micro Password Manager are updated to at least version 5.8.0.1327 to neutralize this threat vector.