First published: Tue Sep 01 2020(Updated: )
Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function, and attain privilege escalation.
Credit: security@trendmicro.com security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trendmicro Apex One | =2019 | |
Trendmicro Apex One | =saas | |
Trendmicro Worry-free Business Security | =10.0-sp1 | |
Microsoft Windows | ||
Trend Micro Apex One | ||
Trend Micro Apex One, OfficeScan, and Worry-Free Business Security | ||
All of | ||
Any of | ||
Trendmicro Apex One | =2019 | |
Trendmicro Apex One | =saas | |
Trendmicro Worry-free Business Security | =10.0-sp1 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24557 is a vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows that allows an attacker to manipulate a product folder, disable security temporarily, abuse a Windows function, and escalate privileges.
CVE-2020-24557 has a severity rating of 7.8 (High).
CVE-2020-24557 affects Trend Micro Apex One, OfficeScan, and Worry-Free Business Security 10.0 SP1 on Microsoft Windows.
An attacker can exploit CVE-2020-24557 by manipulating a specific product folder, temporarily disabling security, abusing a Windows function, and escalating privileges.
You can find more information about CVE-2020-24557 at the following references: [Link 1](https://success.trendmicro.com/solution/000263632), [Link 2](https://www.zerodayinitiative.com/advisories/ZDI-20-1094/), [Link 3](https://success.trendmicro.com/solution/000267260).