Information disclosure in Password Manager for Windows and Password Manager for macOS - CVE-2019-19696
Published: January 17, 2020
Vulnerability identifier: #VU24375
CSH Severity: Low
CVSS v4: 4.8 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2019-19696
CWE-ID: CWE-200
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to improper protection of the generated private key. A local user can gain unauthorized access to private key of the root CA certificate.
Affected software
Password Manager for Windows
Password Manager for macOS
Password Manager for macOS
How to mitigate CVE-2019-19696
Install updates from vendor's website.
Password Manager for Windows - update to 5.0.0.1081
Password Manager for macOS - update to 5.0.1073
Password Manager for macOS - update to 5.0.1073