CVE-2020-8607: Input Validation
An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver could allow an attacker in user-mode with administrator permissions to abuse the driver to modify a kernel address that may cause a system crash or potentially lead to code execution in kernel mode. An attacker must already have obtained administrator access on the target machine (either legitimately or via a separate unrelated attack) to exploit this vulnerability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-8607?
CVE-2020-8607 is an input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver.
How severe is CVE-2020-8607?
CVE-2020-8607 has a severity rating of 6.7 (high).
Which products are affected by CVE-2020-8607?
Multiple Trend Micro products are affected by CVE-2020-8607, including Trendmicro Antivirus Toolkit, Trend Micro Apex One and Worry-Free Business Security, Trendmicro Deep Security, Trendmicro Officescan, Trendmicro Officescan Business Security, Trendmicro Officescan Business Security Service, Trendmicro Officescan Cloud, Trendmicro Online Scan, Trendmicro Portable Security, Trendmicro Rootkit Buster, Trendmicro Safe Lock, and Trendmicro Serverprotect.
What is the risk of CVE-2020-8607?
The risk of CVE-2020-8607 is that an attacker in user-mode with administrator permissions could abuse a driver to modify a kernel address, potentially causing a system crash.
Is there a fix for CVE-2020-8607?
Trend Micro has released patches to address the vulnerability in the affected products. Please refer to the references for more information.