CVE-2020-8607
3Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackepss 0.6%
exploitation probability
0.6%top 55% of all CVEs
observed exploitation
nono source reports it
An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver could allow an attacker in user-mode with administrator permissions to abuse the driver to modify a kernel address that may cause a system crash or potentially lead to code execution in kernel mode. An attacker must already have obtained administrator access on the target machine (either legitimately or via a separate unrelated attack) to exploit this vulnerability.
Affected products
Trend Micro · Trend Micro Anti-Threat Toolkit (ATTK)Trend Micro · Trend Micro Apex OneTrend Micro · Trend Micro Deep SecurityTrend Micro · Trend Micro HouseCallTrend Micro · Trend Micro OfficeScanTrend Micro · Trend Micro Portable SecurityTrend Micro · Trend Micro Rootkit BusterTrend Micro · Trend Micro Safe LockTrend Micro · Trend Micro Security (Consumer Family)Trend Micro · Trend Micro ServerProtectTrend Micro · Trend Micro Worry-Free Business Security