CVE-2020-24557 is a privilege escalation vulnerability affecting Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows, allowing an attacker to temporarily disable security and elevate privileges by manipulating product folders and abusing a Windows function. This vulnerability requires an attacker to already have low-privileged code execution on the target system. Rated 7.8 HIGH (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H), it poses a significant risk due to its potential for full compromise (Confidentiality, Integrity, Availability). The vulnerability is actively exploited in the wild, as confirmed by its presence in the KEV catalog and media coverage, despite no public exploit code being available on platforms like Metasploit or ExploitDB.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:trendmicro:apex_one:-:*:*:*:saas:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:*:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:a:trendmicro:worry-free_business_security:10.0:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.