Description
A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious program to escalate privileges and attain persistence on a vulnerable system.
References (3)
Core 3
Core References
Vendor Advisory x_refsource_misc
https://esupport.trendmicro.com/en-us/home/pages/technical-support/1124099.aspx
Exploit, Third Party Advisory x_refsource_misc
http://hyp3rlinx.altervista.org/advisories/TREND-MICRO-SECURITY-CONSUMER-PERSISTENT-ARBITRARY-CODE-EXECUTION.txt
Exploit, Issue Tracking, Mailing List, Third Party Advisory mailing-list
x_refsource_bugtraq
https://seclists.org/bugtraq/2020/Jan/28
Scores
CVSS v3
7.8
EPSS
0.0018
EPSS Percentile
39.7%
Attack Vector
LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-428
Status
published
Products (8)
trendmicro/antivirus_\+_security_2019
15.0
trendmicro/antivirus_\+_security_2020
16.0
trendmicro/internet_security_2019
15.0
trendmicro/internet_security_2020
16.0
trendmicro/maximum_security_2019
15.0
trendmicro/maximum_security_2020
16.0
trendmicro/premium_security_2019
15.0
trendmicro/premium_security_2020
16.0
Published
Jan 18, 2020
Tracked Since
Feb 18, 2026