PT-2020-16199 · Trend Micro · Trend Micro Security 2020
Abdelhamid Naceri
·
Published
2020-09-28
·
Updated
2020-10-07
·
CVE-2020-25775
CVSS v3.1
6.3
Medium
| Vector | AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Trend Micro Security 2020 version 16
Description
The issue allows an unprivileged user to manipulate the product's secure erase feature to delete files with a higher set of privileges due to a security race condition arbitrary file deletion vulnerability.
Recommendations
For Trend Micro Security 2020 version 16, consider restricting access to the secure erase feature until a patch is available to prevent exploitation of this issue.
Fix
Race Condition
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trend Micro Security 2020