First published: Tue Sep 01 2020(Updated: )
A vulnerability in an Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services dll may allow an attacker to manipulate it to cause an out-of-bounds read that crashes multiple processes in the product. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trendmicro Apex One | =2019 | |
Trendmicro Apex One | =saas | |
Trendmicro Worry-free Business Security | =10.0-sp1 | |
Trendmicro Worry-free Business Security Services | ||
Apple macOS | ||
Microsoft Windows | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24558 is a vulnerability that allows local attackers to disclose sensitive information on affected installations of Trend Micro Apex One.
An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Trend Micro Apex One 2019 and Trend Micro Apex One SAAS are affected.
No, Apple macOS is not vulnerable to CVE-2020-24558.
You can find more information about CVE-2020-24558 at the following references: [Link 1](https://success.trendmicro.com/solution/000263632), [Link 2](https://www.zerodayinitiative.com/advisories/ZDI-20-1095/), [Link 3](https://success.trendmicro.com/solution/000267260).