7.8
CWE
426 427 732
Advisory Published
Updated

CVE-2019-20358

First published: Thu Jan 30 2020(Updated: )

Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed. Another attack vector similar to CVE-2019-9491 was idenitfied and resolved in version 1.62.0.1228 of the tool.

Credit: security@trendmicro.com

Affected SoftwareAffected VersionHow to fix
Trendmicro Anti-threat Toolkit<=1.62.0.1218
Microsoft Windows

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Frequently Asked Questions

  • What is the severity of CVE-2019-20358?

    The severity of CVE-2019-20358 is high due to the potential for arbitrary remote code execution.

  • How do I fix CVE-2019-20358?

    To fix CVE-2019-20358, upgrade to Trend Micro Anti-Threat Toolkit version 1.62.0.1219 or newer.

  • What type of attack does CVE-2019-20358 facilitate?

    CVE-2019-20358 facilitates arbitrary remote code execution through the placement of malicious files in specific directories.

  • Which versions of Trend Micro Anti-Threat Toolkit are affected by CVE-2019-20358?

    Trend Micro Anti-Threat Toolkit versions 1.62.0.1218 and below are affected by CVE-2019-20358.

  • Can CVE-2019-20358 affect other software?

    CVE-2019-20358 specifically affects Trend Micro Anti-Threat Toolkit and does not impact other software directly.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2025 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203