CVE-2020-28575: Trend Micro ServerProtect ioctlMod Heap-based Buffer Overflow Privilege Escalation Vulnerability
A heap-based buffer overflow privilege escalation vulnerability in Trend Micro ServerProtect for Linux 3.0 may allow an attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute high-privileged code on the target in order to exploit this vulnerability.
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro ServerProtect. An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the ioctlMod function. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to escalate privileges and execute code in the context of the kernel.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2020-28575.
What is the severity of CVE-2020-28575?
The severity of CVE-2020-28575 is high with a CVSS score of 8.2.
What is the affected software?
The affected software is Trend Micro ServerProtect version 3.0 on Linux.
How can an attacker exploit CVE-2020-28575?
An attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability.
Is there a fix available for CVE-2020-28575?
Yes, Trend Micro has provided a solution to address this vulnerability. Please refer to the official reference links for more information.