First published: Mon Sep 28 2020(Updated: )
A vulnerability in Trend Micro OfficeScan XG SP1 on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This CVE is similar, but not identical to CVE-2020-24556.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trendmicro Officescan | =xg-sp1 | |
Microsoft Windows | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2020-24562.
The severity of CVE-2020-24562 is high, with a severity value of 7.8.
The affected software is Trend Micro OfficeScan.
This vulnerability can be exploited by local attackers who have obtained the ability to execute low-privileged code on the target system.
No, Microsoft Windows is not vulnerable to CVE-2020-24562.