CVE-2020-25778: Trend Micro Antivirus for Mac Error Message Information Disclosure Vulnerability
This vulnerability allows local attackers to disclose sensitive information on affected installations of Trend Micro Antivirus for Mac. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the KERedirect kext. The issue results from an error message that includes sensitive information. An attacker can leverage this in conjunction with other vulnerabilities to escalate privileges and execute code in the context of the kernel.
Other sources
Trend Micro Antivirus for Mac 2020 (Consumer) has a vulnerability in a specific kernel extension where an attacker could supply a kernel pointer and leak several bytes of memory. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this Trend Micro Antivirus for Mac vulnerability?
The vulnerability ID is CVE-2020-25778.
What is the severity level of CVE-2020-25778?
The severity level of CVE-2020-25778 is medium.
How can this vulnerability be exploited?
This vulnerability can be exploited by local attackers with high-privileged code execution capabilities on the target system.
Which versions of Trend Micro Antivirus for Mac are affected?
Trend Micro Antivirus for Mac versions 2019 and 2020 are affected.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability at the following references: [link1](https://helpcenter.trendmicro.com/en-us/article/TMKA-09948), [link2](https://www.zerodayinitiative.com/advisories/ZDI-20-1241/).