CVE-2019-18190
Trend Micro Security (Consumer) 2020 (v16.x) is affected by a vulnerability in where null pointer dereference errors result in the crash of application, which could potentially lead to possible unsigned code execution under certain circumstances.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.68%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
Trend Micro Security (Consumer) 2020 (v16.x) is affected by a vulnerability in where null pointer dereference errors result in the crash of application, which could potentially lead to possible unsigned code execution under certain circumstances.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.68% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-476
- Affected
- trendmicro/antivirus\+ security 2020 · trendmicro/internet security 2020 · trendmicro/maximum security 2020 · trendmicro/premium security 2020
- Source
- security@trendmicro.com
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.