CVE-2020-8607
6.7
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Exploitability: 0.8 / Impact: 5.9
Source: NVD
Description
An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver could allow an attacker in user-mode with administrator permissions to abuse the driver to modify a kernel address that may cause a system crash or potentially lead to code execution in kernel mode. An attacker must already have obtained administrator access on the target machine (either legitimately or via a separate unrelated attack) to exploit this vulnerability.
Affected (24)
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 1.62.1240 | |
| Version 2019 | |
| Version 10.0 | |
| Version xg sp1 | |
| Version 10.0 sp1 | |
| All versions | |
| Version 15 | |
| Version 8.0 | |
| Version 2.0 | |
| Version 2.2 | |
| All versions | |
| Version 5.8 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows | All versions |
References (8)
Source: security@trendmicro.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.