CVE-2020-8602
A vulnerability in the management consoles of Trend Micro Deep Security 10.0-12.0 and Trend Micro Vulnerability Protection 2.0 SP2 may allow an authenticated attacker with full control privileges to bypass file integrity checks, leading to remote code…
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.23%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability in the management consoles of Trend Micro Deep Security 10.0-12.0 and Trend Micro Vulnerability Protection 2.0 SP2 may allow an authenticated attacker with full control privileges to bypass file integrity checks, leading to remote code execution.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.23% probability · 90th percentile
- CISA KEV
- Not listed
- Affected
- trendmicro/deep security manager · trendmicro/vulnerability protection
- Source
- security@trendmicro.com
References
- https://success.trendmicro.com/solution/000252039Patch, Vendor Advisory
- https://success.trendmicro.com/solution/000252039Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.