Skip to content
COOEY

EXPOSURES › CVE-2020-24557

CVE-2020-24557

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-24557 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 75/100 exploited-in-wildunpatchedprivilege-escalation

Trend Micro Apex One, OfficeScan, and Worry-Free Business Security suffered an improper access control flaw allowing attackers to disable security and escalate privileges.

An improper access control vulnerability in Trend Micro's Apex One, OfficeScan, and Worry-Free Business Security allowed attackers to manipulate product folders to disable security temporarily and escalate privileges. DIB organizations must ensure these products are patched and monitored, as the flaw could compromise endpoint security and violate compliance requirements. The vulnerability was actively exploited, indicating a significant threat to systems relying on these security tools.

Shame score — A security vendor's own product contained a critical flaw that allowed attackers to disable security and escalate privileges, demonstrating severe negligence in product hardening and patch management.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function, and attain privilege escalation.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
CVE-2020-24557 is a critical privilege escalation flaw in Trend Micro's endpoint security suite, allowing attackers to disable security and escalate privileges via improper access controls. The vulner
cooey ↗ severe-fallout -0.80
NIST documents the vulnerability as a critical improper access control flaw enabling privilege escalation, reflecting severe fallout and condemnation of the security gap.
"Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function, and attain privilege escalation."
www.cvefind.com ↗ severe-fallout +0.00
Neutral database listing CVE without commentary on vendor handling.
recentbreaches.com ↗ severe-fallout +0.00
Neutral breach tracker with no mention of Trend Micro or CVE-2020-24557.
xposedornot.com ↗ severe-fallout +0.00
Neutral breach directory with no mention of Trend Micro or CVE-2020-24557.
california.public.law ↗ severe-fallout +0.00
Neutral legal code unrelated to vendor sentiment.
NIST ↗ severe-fallout +0.00
Neutral NIST homepage without CVE-2020-24557 commentary.
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Trend Micro Cloud One for Government
Trend Micro Inc.
In Process
Trend Micro Vision One for Government
Trend Micro Inc.
In Process