9.8

CVE-2019-18190

Trend Micro Security (Consumer) 2020 (v16.x) is affected by a vulnerability in where null pointer dereference errors result in the crash of application, which could potentially lead to possible unsigned code execution under certain circumstances.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Antivirus+ Security 2020 Version >= 16.0 < 16.0.1227
   Microsoft ≫ Windows Version -
Trendmicro ≫ Internet Security 2020 Version >= 16.0 < 16.0.1227
   Microsoft ≫ Windows Version -
Trendmicro ≫ Maximum Security 2020 Version >= 16.0 < 16.0.1227
   Microsoft ≫ Windows Version -
Trendmicro ≫ Premium Security 2020 Version >= 16.0 < 16.0.1227
   Microsoft ≫ Windows Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.68% 0.839
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
NIST 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.

https://esupport.trendmicro.com/en-us/home/pages/technical-support/1124031.aspx
Vendor Advisory