Vulnerability

Hackers use Trend Micro Antivirus Flaw to Gain Windows Systems Admin Rights

Hackers use Trend Micro Antivirus Flaw to gain Windows systems admin rights. This vulnerability which is found in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a particular product folder to disable the security temporarily and abuse a specific Windows function and attain privilege escalation. 

Affected Versions and Target Products

  • The version 1909 (OS Build 18363.719) of Microsoft Windows 10 mitigates hard links, but previous versions are affected.
  • Trend Micro Apex One (Apex One) 2019 Build Less than 8422
  • Trend Micro Apex One SaaS (Apex One SaaS) Build less than 202008
  • OfficeScan Corporate Edition (hereafter OfficeScan) XG Service Pack 1 Build Less than 5702

Vulnerability (CVE-2020-24557) in Trend Micro Apex One, Apex One SaaS, and OfficeScan Corporate Edition and Patches:

Trend Micro has released new patches for Trend Micro Apex One, Apex One as a Service (SaaS), and OfficeScan XG SP1.  These patches resolve multiple vulnerabilities related to hard link privilege escalation, out-of-bounds read information disclosure, and improper access control. 

The hotfixes are cumulative, and the latest hotfixes include fixes for this vulnerability.

ProductAbout the hotfix
ApexOneCritical Patch 8422
OfficeScan Corp. XG SP1Critical Patch 5702
Hotfixes

Trend Micro has also updated their previous vulnerability patch releases.

CVE Identifier(s): CVE-2020-24556, CVE-2020-24557, CVE-2020-24558, CVE-2020-24559, CVE-2020-24562

Impacts that can be seen in case of attacks:

Known vulnerabilities in Apex One, Apex One SaaS, and OfficeScan agents could elevate privileges, allow an attacker to manipulate certain product folders to temporarily disable security features or to temporarily disable certain Windows features. It may be abused.

Conclusion:

It is very important to apply the latest patch as soon as possible. Patches are released for every version now. Utilize and save the environment!

Also Read

Critical Bugs in EtherNet/IP Stack Expose Industrial Systems to DoS, Data Leaks, and RCE Attacks

NSA Releases List of Top 5 vulnerabilities Exploited by Russian Hackers

Guru Baran

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Recent Posts

Hackers Target AI Infrastructure With RCE, Prompt Injection and API Key Theft

Hackers are actively probing AI systems, turning exposed gateways and agent tools into routes for…

5 hours ago

Hackers Make Phishing Pages Change Their Code Every Time Someone Opens Them

Hackers are making some phishing pages harder to track by changing the code delivered to…

5 hours ago

Iran-Linked Hackers Reportedly Knock UK Power Plant Offline for Four Days

A cyber incident reportedly forced a British power plant to halt operations for about four…

6 hours ago

Russian Hackers Use New HOOKEDGE Malware to Spy on European Defense and Diplomatic Targets

Russian hackers have used a new backdoor called HOOKEDGE to target defense manufacturers, government bodies,…

6 hours ago

Ransomware Gang Claims AI Can Analyze 700GB of Stolen Data Every Hour

TITAN ransomware is pairing file encryption with an ambitious claim: artificial intelligence that can sort…

7 hours ago

Hackers Compromise Hundreds of WordPress Sites to Deploy Amatera Stealer via ClickFix

A fake student resume is being used to place a remote-access tool on researchers’ Windows…

8 hours ago