PT-2020-6112 · Microsoft+1 · Windows+4
Kharosx0
·
Published
2020-03-16
·
Updated
2022-04-28
·
CVE-2020-24556
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Trend Micro Apex One (affected versions not specified)
Trend Micro OfficeScan XG SP1 (affected versions not specified)
Trend Micro Worry-Free Business Security 10 SP1 (affected versions not specified)
Trend Micro Worry-Free Business Security Services (affected versions not specified)
Microsoft Windows (versions prior to 1909, OS Build 18363.719)
Description
A vulnerability in the mentioned Trend Micro products on Microsoft Windows may allow an attacker to create a hard link to any file on the system, potentially leading to privilege escalation and code execution. The attacker must first obtain the ability to execute low-privileged code on the target system. The issue is related to insufficient access control in the Security Agent component of the affected Trend Micro products.
Recommendations
For Trend Micro Apex One, consider restricting access to sensitive files and directories until a patch is available.
For Trend Micro OfficeScan XG SP1, temporarily disable any features that may allow the creation of hard links to system files.
For Trend Micro Worry-Free Business Security 10 SP1, avoid using the Security Agent component until the issue is resolved.
For Trend Micro Worry-Free Business Security Services, restrict access to the vulnerable component to minimize the risk of exploitation.
For Microsoft Windows versions prior to 1909 (OS Build 18363.719), update to version 1909 or later to mitigate the risk of hard link exploitation.
Fix
Link Following
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trend Micro Apex One
Trend Micro Officescan Xg Sp1
Trend Micro Worry-Free Business Security 10 Sp1
Trend Micro Worry-Free Business Security Services
Windows