7.2
CVE-2020-8607
- EPSS 0.66%
- Veröffentlicht 05.08.2020 14:15:13
- Zuletzt bearbeitet 21.11.2024 05:39:07
- Erkennungen
An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver could allow an attacker in user-mode with administrator permissions to abuse the driver to modify a kernel address that may cause a system crash or potentially lead to code execution in kernel mode. An attacker must already have obtained administrator access on the target machine (either legitimately or via a separate unrelated attack) to exploit this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Antivirus Toolkit Version < 1.62.1240
Trendmicro ≫ Apex One Version 2019
Trendmicro ≫ Apex One Version saas
Trendmicro ≫ Deep Security Version 9.6
Trendmicro ≫ Deep Security Version 10.0
Trendmicro ≫ Deep Security Version 11.0
Trendmicro ≫ Deep Security Version 12.0
Trendmicro ≫ Officescan Version xg Update sp1
Trendmicro ≫ Officescan Business Security Version 9.0
Trendmicro ≫ Officescan Business Security Version 9.5
Trendmicro ≫ Officescan Business Security Version 10.0 Update sp1
Trendmicro ≫ Officescan Business Security Service Version -
Trendmicro ≫ Officescan Cloud Version 15
Trendmicro ≫ Officescan Cloud Version 16.0
Trendmicro ≫ Online Scan Version 8.0
Trendmicro ≫ Portable Security Version 2.0
Trendmicro ≫ Portable Security Version 3.0
Trendmicro ≫ Rootkit Buster Version 2.2
Trendmicro ≫ Safe Lock Version - SwEdition txone
Trendmicro ≫ Safe Lock Version 2.0 Update sp1 SwEdition -
Trendmicro ≫ Serverprotect Version 5.8 SwPlatform emc
Trendmicro ≫ Serverprotect Version 5.8 SwPlatform netware
Trendmicro ≫ Serverprotect Version 5.8 SwPlatform windows
Trendmicro ≫ Serverprotect Version 6.0 SwPlatform storage
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.66% | 0.465 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://jvn.jp/en/vu/JVNVU99160193/index.html
https://jvn.jp/vu/JVNVU99160193/
https://success.trendmicro.com/jp/solution/000260748
https://success.trendmicro.com/solution/000260713