CVE-2020-24557
Trend Micro Apex One, Trend Micro Worry-Free Business Security
Published 1 Sept 2020 · updated 17 Jun 2026 · Analyzed
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 3 Nov 2021, with a remediation deadline of 3 May 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function and attain privilege escalation. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Please note that version 1909 (OS Build 18363.719) of Microsoft Windows 10 mitigates hard links, but previous versions are affected.
References
- success.trendmicro.com/solution/000263632 · Vendor Advisory
- success.trendmicro.com/solution/000267260 · Vendor Advisory
- www.zerodayinitiative.com/advisories/ZDI-20-1094/ · Third Party Advisory, VDB Entry
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-24557 · US Government Resource