CVE-2020-15602

HIGHCVSS 7.8/10EPSS 1.00%

Last modified

CVE-2020-15602 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. An untrusted search path remote code execution (RCE) vulnerability in the Trend Micro Secuity 2020 (v16.0.0.1146 and below) consumer family of products could allow an attacker to run arbitrary code on a vulnerable system. As the Trend Micro installer tries to load DLL files from its current directory, an arbitrary DLL could also be loaded with the same privileges as the installer if run as Administrator. EPSS estimates a 1.00% chance of exploitation in the next 30 days.

Description

An untrusted search path remote code execution (RCE) vulnerability in the Trend Micro Secuity 2020 (v16.0.0.1146 and below) consumer family of products could allow an attacker to run arbitrary code on a vulnerable system. As the Trend Micro installer tries to load DLL files from its current directory, an arbitrary DLL could also be loaded with the same privileges as the installer if run as Administrator. User interaction is required to exploit the vulnerbaility in that the target must open a malicious directory or device.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Probability
1.00%

58.4th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
TrendmicroAntivirus\+ 2020<= 16.0.1146
TrendmicroInternet Security 2020<= 16.0.1146
TrendmicroMaximum Security 2020<= 16.0.1146
TrendmicroPremium Security 2020<= 16.0.1146

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-15602?
An untrusted search path remote code execution (RCE) vulnerability in the Trend Micro Secuity 2020 (v16.0.0.1146 and below) consumer family of products could allow an attacker to run arbitrary code on a vulnerable system. As the Trend Micro installer tries to load DLL files from its current directory, an arbitrary DLL could also be loaded with the same privileges as the installer if run as Administrator. User interaction is required to exploit the vulnerbaility in that the target must open a malicious directory or device.
How severe is CVE-2020-15602?
CVE-2020-15602 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 1.00% probability of exploitation in the next 30 days.
How do I fix CVE-2020-15602?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-15602?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST