IT

Tracker / CVE-2020-8607

CVE-2020-8607

Medium 6.7

An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver could allow an attacker in user-mode with administrator permissions to abuse the driver to modify a kernel address that may cause a system crash or potentially lead to code execution in kernel mode. An attacker must already have obtained administrator access on the target machine (either legitimately or via a separate unrelated attack) to exploit this vulnerability.

Affected products and versions

trendmicro antivirus_toolkit · … → 1.62.1240
trendmicro apex_one
trendmicro deep_security
trendmicro officescan
trendmicro officescan_business_security
trendmicro officescan_business_security_service
trendmicro officescan_cloud
trendmicro online_scan
trendmicro portable_security
trendmicro rootkit_buster
trendmicro safe_lock
trendmicro serverprotect

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References