7.1

CVE-2020-24558

A vulnerability in an Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services dll may allow an attacker to manipulate it to cause an out-of-bounds read that crashes multiple processes in the product. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Apex One Version 2019
   Apple ≫ macOS Version -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex One Version saas
   Apple ≫ macOS Version -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Worry-free Business Security Version 10.0 Update sp1
   Apple ≫ macOS Version -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Worry-free Business Security Services Version -
   Apple ≫ macOS Version -
   Microsoft ≫ Windows Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.56% 0.418
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.1 1.8 5.2
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
NIST 3.6 3.9 4.9
AV:L/AC:L/Au:N/C:P/I:N/A:P
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.

https://success.trendmicro.com/solution/000263632
Vendor Advisory
Product
https://success.trendmicro.com/solution/000267260
Vendor Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-1095/
Third Party Advisory
VDB Entry