Tracker / CVE-2020-8607
CVE-2020-8607
Medium 6.7
An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver could allow an attacker in user-mode with administrator permissions to abuse the driver to modify a kernel address that may cause a system crash or potentially lead to code execution in kernel mode. An attacker must already have obtained administrator access on the target machine (either legitimately or via a separate unrelated attack) to exploit this vulnerability.
Affected products and versions
| trendmicro | antivirus_toolkit · … → 1.62.1240 |
|---|---|
| trendmicro | apex_one |
| trendmicro | deep_security |
| trendmicro | officescan |
| trendmicro | officescan_business_security |
| trendmicro | officescan_business_security_service |
| trendmicro | officescan_cloud |
| trendmicro | online_scan |
| trendmicro | portable_security |
| trendmicro | rootkit_buster |
| trendmicro | safe_lock |
| trendmicro | serverprotect |
Analysis
This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.