PT-2020-16203 · Trend Micro · Trend Micro Antivirus For Mac
Dhiraj Mishra
+1
·
Published
2020-10-13
·
Updated
2022-05-03
·
CVE-2020-25779
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N |
Name of the Vulnerable Software and Affected Versions
Trend Micro Antivirus for Mac 2020 (Consumer)
Description
The issue allows an Internationalized Domain Name homograph attack, also known as a Puny-code attack, to be used for adding a malicious website to the list of approved websites. This can bypass the web threat protection feature.
Recommendations
For Trend Micro Antivirus for Mac 2020 (Consumer), consider restricting access to the feature that allows adding websites to the approved list until a fix is available. As a temporary workaround, manually monitor and verify the approved websites list to prevent malicious additions.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trend Micro Antivirus For Mac