Junglewise Threat Intelligence

CVE-2020-24557: Trend Micro Multiple Products Improper Access Control Vulnerability

CVE-2020-24557 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Technologies: Trend Micro Officescan. Vendors: Trend Micro.

Executive brief

Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Windows contain an improper access control vulnerability. A local attacker with low-privileged code execution can manipulate specific product folders to disable security features and abuse Windows functions to achieve privilege escalation.

Affected products

  • Trend Micro Apex One 2019, SaaS
  • Trend Micro Worry-Free Business Security 10.0 SP1
  • Trend Micro OfficeScan

Timeline

  • 2020-09-08: disclosed: Initial NVD analysis date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Confirmed exploited in the wild per CISA KEV catalog entry date

Related threats