9.8

CVE-2019-18190

Trend Micro Security (Consumer) 2020 (v16.x) is affected by a vulnerability in where null pointer dereference errors result in the crash of application, which could potentially lead to possible unsigned code execution under certain circumstances.

Daten sind bereitgestellt durch National Vulnerability Database (NVD)
TrendmicroAntivirus+ Security 2020 Version >= 16.0 < 16.0.1227
   MicrosoftWindows Version-
TrendmicroInternet Security 2020 Version >= 16.0 < 16.0.1227
   MicrosoftWindows Version-
TrendmicroMaximum Security 2020 Version >= 16.0 < 16.0.1227
   MicrosoftWindows Version-
TrendmicroPremium Security 2020 Version >= 16.0 < 16.0.1227
   MicrosoftWindows Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.73% 0.715
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvd@nist.gov 7.5 10 6.4
AV:N/AC:L/Au:N/C:P/I:P/A:P
CWE-476 NULL Pointer Dereference

The product dereferences a pointer that it expects to be valid but is NULL.