PT-2020-20231 · Trend Micro · Trend Micro Vulnerability Protection
Published
2020-02-20
·
Updated
2020-02-25
·
CVE-2020-8601
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Trend Micro Vulnerability Protection version 2.0
Description
The issue allows an attack to use the product installer to load other DLL files located in the same directory.
Recommendations
For Trend Micro Vulnerability Protection version 2.0, consider restricting access to the directory where the product installer is located to prevent unauthorized loading of DLL files until a fix is available.
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trend Micro Vulnerability Protection