First published: Tue Sep 01 2020(Updated: )
A vulnerability in Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services on macOS may allow an attacker to manipulate a certain binary to load and run a script from a user-writable folder, which then would allow them to execute arbitrary code as root. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trendmicro Apex One | =2019 | |
Trendmicro Apex One | =saas | |
Trendmicro Officescan | =xg-sp1 | |
Apple macOS | ||
Trendmicro Worry-free Business Security | =10.0-sp1 | |
Trendmicro Worry-free Business Security Services | ||
Microsoft Windows | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-24559 is a vulnerability in Trend Micro Apex One that allows local attackers to escalate privileges.
An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The affected software includes Trend Micro Apex One versions 2019, Trend Micro Apex One SaaS, and Trendmicro Officescan XG SP1.
CVE-2020-24559 has a severity level of 7.8 (high).
You can find more information about CVE-2020-24559 at the following references: [Link 1](https://success.trendmicro.com/solution/000263632), [Link 2](https://www.zerodayinitiative.com/advisories/ZDI-20-1096/), [Link 3](https://success.trendmicro.com/solution/000267260).