CVE-2020-24557
KEVlargeImproper Access Control LPE in Trend Micro Apex One and Worry-Free Business Security
CISA: Trend Micro Multiple Products Improper Access Control Vulnerability
Trend Micro Apex One, OfficeScan, and Worry-Free Business Security 10.0 SP1 on Microsoft Windows contain an improper access control flaw that lets an attacker manipulate a specific product folder to temporarily disable the security product and abuse a Windows function to escalate privileges. The attacker must first obtain the ability to execute low-privileged code on the target system; Windows 10 version 1909 (OS Build 18363.719) mitigates the hard-link technique, so earlier Windows versions are the easier targets. Successful exploitation yields local privilege escalation with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8). Any organization running these Trend Micro endpoint agents on unpatched Windows machines is affected, with exposure driven by fleet size rather than internet-facing services. The vulnerability is being exploited in the wild per vendor advisories and news coverage, and CISA added it to the KEV catalog on 2021-11-03 with the required action of applying vendor updates; no public proof-of-concept is documented.
What to do: Apply Trend Micro's patched builds for Apex One and Worry-Free Business Security 10.0 SP1 per the vendor advisory, as CISA's required action directs. Prioritize hosts running Windows versions older than Windows 10 1909 (OS Build 18363.719), where the hard-link mitigation is absent, and verify no unpatched agents remain in your fleet. Also check endpoints for signs of prior low-privileged code execution and local privilege escalation, since the flaw requires an existing foothold to exploit.
| Trend Micro Apex One | — |
| Trend Micro OfficeScan | — |
| Trend Micro Worry-Free Business Security | 10.0 SP1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function and attain privilege escalation. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Please note that version 1909 (OS Build 18363.719) of Microsoft Windows 10 mitigates hard links, but previous versions are affected.
- Affected
- Trend Micro Apex One, OfficeScan, and Worry-Free Business Security
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- trendmicro
- Products
- apex one, worry-free business security
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H