Show filters
493 Total Results
Displaying 261-270 of 493
Sort by:
Attacker Value
Unknown

CVE-2020-24563

Disclosure Date: September 29, 2020 (last updated February 22, 2025)
A vulnerability in Trend Micro Apex One may allow a local attacker to manipulate the process of the security agent unload option (if configured), which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability to execute low-privileged code on the target in order to exploit this vulnerability.
Attacker Value
Unknown

CVE-2020-25771

Disclosure Date: September 29, 2020 (last updated February 22, 2025)
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute low-privileged code on the target in order to exploit these vulnerabilities. The subs affected in this vulnerability makes it unique compared to similar CVEs such as CVE-2020-24564 and CVE-2020-25770.
Attacker Value
Unknown

CVE-2020-25773

Disclosure Date: September 29, 2020 (last updated February 22, 2025)
A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to execute arbitrary code on affected products. User interaction is required to exploit this vulnerability in that the target must import a corrupted configuration file.
Attacker Value
Unknown

CVE-2020-25770

Disclosure Date: September 29, 2020 (last updated February 22, 2025)
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute low-privileged code on the target in order to exploit these vulnerabilities. The subs affected in this vulnerability makes it unique compared to similar CVEs such as CVE-2020-24564 and CVE-2020-25771.
Attacker Value
Unknown

CVE-2020-24564

Disclosure Date: September 29, 2020 (last updated February 22, 2025)
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute low-privileged code on the target in order to exploit these vulnerabilities. The subs affected in this vulnerability makes it unique compared to similar CVEs such as CVE-2020-24565 and CVE-2020-25770.
Attacker Value
Unknown

CVE-2020-25775

Disclosure Date: September 29, 2020 (last updated February 22, 2025)
The Trend Micro Security 2020 (v16) consumer family of products is vulnerable to a security race condition arbitrary file deletion vulnerability that could allow an unprivileged user to manipulate the product's secure erase feature to delete files with a higher set of privileges.
Attacker Value
Unknown

CVE-2020-24560

Disclosure Date: September 24, 2020 (last updated February 22, 2025)
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of the expected one. CWE-295: Improper server certificate verification in the communication with the update server.
Attacker Value
Unknown

CVE-2020-15604

Disclosure Date: September 24, 2020 (last updated February 22, 2025)
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of the expected one. CWE-494: Update files are not properly verified.
Attacker Value
Unknown

CVE-2020-24561

Disclosure Date: September 15, 2020 (last updated February 22, 2025)
A command injection vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow an attacker to execute arbitrary code on an affected system. An attacker must first obtain admin/root privileges on the SPLX console to exploit this vulnerability.
Attacker Value
Unknown

CVE-2020-24559

Disclosure Date: September 01, 2020 (last updated February 22, 2025)
A vulnerability in Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services on macOS may allow an attacker to manipulate a certain binary to load and run a script from a user-writable folder, which then would allow them to execute arbitrary code as root. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.