CVE-2019-19693: Trend Micro Maximum Security Link Resolution Information Disclosure And Denial-of-Service Vulnerability
The Trend Micro Security 2020 consumer family of products contains a vulnerability that could allow a local attacker to disclose sensitive information or to create a denial-of-service condition on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Other sources
This vulnerability allows local attackers to disclose sensitive information or to create a denial-of-service condition on affected installations of Trend Micro Maximum Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the handling of junctions. By creating a junction, an attacker can abuse the service to delete arbitrary files. An attacker can leverage this vulnerability to disclose sensitive information or to create a denial-of-service condition on the system.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2019-19693.
What is the severity of CVE-2019-19693?
CVE-2019-19693 has a severity rating of 7.1 (high).
How can an attacker exploit CVE-2019-19693?
An attacker must first obtain the ability to execute low-privileged code on the target system to exploit CVE-2019-19693.
What software versions are affected by CVE-2019-19693?
CVE-2019-19693 affects Trendmicro Antivirus + Security 2020, Trendmicro Internet Security 2020, Trendmicro Maximum Security 2020, and Trendmicro Premium Security 2020 with versions between 16.0 and 16.0.1249.
How can I fix CVE-2019-19693?
To fix CVE-2019-19693, apply the latest security patches provided by Trend Micro and ensure you are using the latest version of Trend Micro Maximum Security.