ZeroHour

CVE-2020-24557

KEVlarge

Improper Access Control LPE in Trend Micro Apex One and Worry-Free Business Security

CISA: Trend Micro Multiple Products Improper Access Control Vulnerability

CVSS 3.1
7.8 high
EPSS
3%p85
Published
()
KEV added
AI analysis

Trend Micro Apex One, OfficeScan, and Worry-Free Business Security 10.0 SP1 on Microsoft Windows contain an improper access control flaw that lets an attacker manipulate a specific product folder to temporarily disable the security product and abuse a Windows function to escalate privileges. The attacker must first obtain the ability to execute low-privileged code on the target system; Windows 10 version 1909 (OS Build 18363.719) mitigates the hard-link technique, so earlier Windows versions are the easier targets. Successful exploitation yields local privilege escalation with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8). Any organization running these Trend Micro endpoint agents on unpatched Windows machines is affected, with exposure driven by fleet size rather than internet-facing services. The vulnerability is being exploited in the wild per vendor advisories and news coverage, and CISA added it to the KEV catalog on 2021-11-03 with the required action of applying vendor updates; no public proof-of-concept is documented.

What to do: Apply Trend Micro's patched builds for Apex One and Worry-Free Business Security 10.0 SP1 per the vendor advisory, as CISA's required action directs. Prioritize hosts running Windows versions older than Windows 10 1909 (OS Build 18363.719), where the hard-link mitigation is absent, and verify no unpatched agents remain in your fleet. Also check endpoints for signs of prior low-privileged code execution and local privilege escalation, since the flaw requires an existing foothold to exploit.

Affected
Trend Micro Apex One
Trend Micro OfficeScan
Trend Micro Worry-Free Business Security10.0 SP1
Estimated exposure
largehundreds of thousands of managed Windows endpoints (order-of-magnitude estimate) — No public install counts were provided in the data, so the estimate extrapolates from the typical deployment base of mainstream Trend Micro SMB/enterprise endpoint-security agents on corporate Windows machines.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function and attain privilege escalation. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Please note that version 1909 (OS Build 18363.719) of Microsoft Windows 10 mitigates hard links, but previous versions are affected.

CISA Known Exploited Vulnerability
Affected
Trend Micro Apex One, OfficeScan, and Worry-Free Business Security
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
trendmicro
Products
apex one, worry-free business security
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news