First published: Mon Sep 28 2020(Updated: )
A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to trigger an out-of-bounds red information disclosure which would disclose sensitive information to an unprivileged account. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro OfficeScan | ||
Trendmicro Apex One | =2019 | |
Trendmicro Apex One | =saas | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25774 is a vulnerability that allows remote attackers to disclose sensitive information on affected installations of Trend Micro OfficeScan ServerMigrationTool.
To exploit CVE-2020-25774, user interaction is required. The target must visit a malicious page or open a malicious file.
Trend Micro OfficeScan ServerMigrationTool, specifically versions 2019 and saas, are affected by CVE-2020-25774.
CVE-2020-25774 has a severity value of 4.3, which is considered medium.
To fix CVE-2020-25774, it is recommended to update to the latest version of Trend Micro OfficeScan ServerMigrationTool and follow the recommendations provided by the vendor.