EXPOSURES › CVE-2020-24557
CVE-2020-24557
HIGH ⌖ ON CISA KEV · EXPLOITEDTrend Micro Apex One, OfficeScan, and Worry-Free Business Security suffered an improper access control flaw allowing attackers to disable security and escalate privileges.
An improper access control vulnerability in Trend Micro's Apex One, OfficeScan, and Worry-Free Business Security allowed attackers to manipulate product folders to disable security temporarily and escalate privileges. DIB organizations must ensure these products are patched and monitored, as the flaw could compromise endpoint security and violate compliance requirements. The vulnerability was actively exploited, indicating a significant threat to systems relying on these security tools.
Shame score — A security vendor's own product contained a critical flaw that allowed attackers to disable security and escalate privileges, demonstrating severe negligence in product hardening and patch management.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function, and attain privilege escalation.
"Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function, and attain privilege escalation."
| PRODUCT | STATUS |
|---|---|
| Trend Micro Cloud One for Government Trend Micro Inc. |
In Process |
| Trend Micro Vision One for Government Trend Micro Inc. |
In Process |