ZeroHour

CVE-2020-8607

CVSS 3.1
6.7 medium
EPSS
<1%p44
Published
()
Modified
Description

An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver could allow an attacker in user-mode with administrator permissions to abuse the driver to modify a kernel address that may cause a system crash or potentially lead to code execution in kernel mode. An attacker must already have obtained administrator access on the target machine (either legitimately or via a separate unrelated attack) to exploit this vulnerability.

Vendors
trendmicro
Products
antivirus toolkit, apex one, deep security, officescan, officescan business security, officescan business security service, officescan cloud, online scan, portable security, rootkit buster, safe lock, serverprotect
Weakness
CWE-20
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.