← Back

CVE-2020-15604

nvd nist
Published: Sep 24, 2020Modified: Jun 17, 2026

JSON object

Loading...
7.5
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
Exploitability: 3.9 / Impact: 3.6
Source: NVD

Description

An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of the expected one. CWE-494: Update files are not properly verified.

Affected (5)

5 products
Antivirus+ 2019
Internet Security 2019
Maximum Security 2019
Officescan Cloud
Premium Security 2019
Configuration A
5 vulnerable · 1 platform
Vulnerable SoftwareAffected Versions
Up to 15.0
Up to 15.0
Up to 15.0
Version 15
Up to 15.0
Running on/withPlatform Versions
Microsoft
Windows
All versions

References (8)

Source: security@trendmicro.com
Vendor Advisory
Source: security@trendmicro.com
Vendor Advisory
Source: security@trendmicro.com
Third Party Advisory
Source: security@trendmicro.com
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory

Timeline

No history available yet.