CVE-2020-24557
CVE-2020-24557
In short
A flaw in Trend Micro Apex One and Worry-Free Business Security allows someone with basic access to a Windows computer to trick the product into lowering its defenses and then gain higher privileges on the system. This only works on older Windows 10 versions.
Technical detail
A privilege escalation vulnerability exists in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Windows, exploitable via manipulation of product folders combined with Windows hard links. Requires low-privileged code execution on the target system; Windows 10 Build 18363.719 and later mitigate the attack vector, but earlier versions remain vulnerable.
Summary generated and translated by AI from the official description.
A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function and attain privilege escalation. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Please note that version 1909 (OS Build 18363.719) of Microsoft Windows 10 mitigates hard links, but previous versions are affected.
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Trend Micro · Trend Micro Apex OneTrend Micro · Trend Micro Worry-Free Business SecurityWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →