CVE-2020-27013
Trend Micro Antivirus for Mac 2020 (Consumer) contains a vulnerability in the product that occurs when a webserver is started that implements an API with several properties that can be read and written to allowing the attacker to gather and modify…
Does this matter?
Lower severity and a low EPSS score (0.44%). Track it; it rarely justifies an emergency change on its own.
Description
Trend Micro Antivirus for Mac 2020 (Consumer) contains a vulnerability in the product that occurs when a webserver is started that implements an API with several properties that can be read and written to allowing the attacker to gather and modify sensitive product and user data. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
- CVSS 3.1
- 4.4 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
- EPSS
- 0.44% probability · 37th percentile
- CISA KEV
- Not listed
- Affected
- trendmicro/antivirus
- Source
- security@trendmicro.com
References
- https://helpcenter.trendmicro.com/en-us/article/TMKA-09950Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-1243/Third Party Advisory, VDB Entry
- https://helpcenter.trendmicro.com/en-us/article/TMKA-09950Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-1243/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.