7.8

CVE-2020-24559

A vulnerability in Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services on macOS may allow an attacker to manipulate a certain binary to load and run a script from a user-writable folder, which then would allow them to execute arbitrary code as root. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Apex One Version 2019
   Apple ≫ macOS Version -
Trendmicro ≫ Apex One Version saas
   Apple ≫ macOS Version -
Trendmicro ≫ Officescan Version xg Update sp1
   Apple ≫ macOS Version -
Trendmicro ≫ Worry-free Business Security Version 10.0 Update sp1
   Apple ≫ macOS Version -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Worry-free Business Security Services Version -
   Apple ≫ macOS Version -
   Microsoft ≫ Windows Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.79% 0.513
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 7.2 3.9 10
AV:L/AC:L/Au:N/C:C/I:C/A:C
CWE-59 Improper Link Resolution Before File Access ('Link Following')

The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

https://success.trendmicro.com/solution/000263632
Vendor Advisory
https://success.trendmicro.com/solution/000267260
Vendor Advisory
https://www.zerodayinitiative.com/advisories/ZDI-20-1096/
Third Party Advisory
VDB Entry