CVE-2020-25777

MEDIUM

Trend Micro Antivirus for Mac 2020 - Auth Bypass

Title source: llm
STIX 2.1

Description

Trend Micro Antivirus for Mac 2020 (Consumer) is vulnerable to a specific kernel extension request attack where an attacker could bypass the Web Threat Protection feature of the product. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

References (2)

Core 2
Core References
Patch, Vendor Advisory x_refsource_misc
https://helpcenter.trendmicro.com/en-us/article/TMKA-09947
Third Party Advisory, VDB Entry x_refsource_misc
https://www.zerodayinitiative.com/advisories/ZDI-20-1242/

Scores

CVSS v3 5.4
EPSS 0.0026
EPSS Percentile 49.2%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N

Details

Status published
Products (2)
trendmicro/antivirus 2019
trendmicro/antivirus 2020
Published Oct 14, 2020
Tracked Since Feb 18, 2026