First published: Mon Sep 28 2020(Updated: )
The Trend Micro Security 2020 (v16) consumer family of products is vulnerable to a security race condition arbitrary file deletion vulnerability that could allow an unprivileged user to manipulate the product's secure erase feature to delete files with a higher set of privileges.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro Maximum Security 2022 | ||
Trend Micro Antivirus+ 2020 | <=16.0 | |
Trend Micro Internet Security | <=16.0 | |
Trend Micro Maximum Security | <=16.0 | |
Trend Micro Premium Security 2020 | <=16.0 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-25775 has a medium severity rating due to its potential for arbitrary file deletion.
To fix CVE-2020-25775, users should update their Trend Micro Security products to the latest available version that addresses this vulnerability.
CVE-2020-25775 affects Trend Micro Maximum Security 2020, Internet Security 2020, and Antivirus+ 2020.
An unprivileged user can exploit CVE-2020-25775 to manipulate the secure erase feature of the vulnerable Trend Micro products.
CVE-2020-25775 is a security race condition vulnerability that allows for arbitrary file deletion.