Remote Code Execution Vulnerability in Trend Micro Security Products
CVE-2020-15602
Key Information:
- Vendor
Trend Micro
- Vendor
- CVE Published:
- 15 July 2020
What is CVE-2020-15602?
An untrusted search path vulnerability exists in the Trend Micro Security 2020 product line, allowing attackers to execute arbitrary code on affected systems. This vulnerability arises when the Trend Micro installer attempts to load dynamic link library (DLL) files from its own directory. If the installer is executed with administrator privileges, it becomes susceptible to exploitation when the user opens a malicious directory or device. For a successful attack, user interaction is required, making this a significant concern for potential risk exposure.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Trend Micro Security (Consumer) 2020 (v16)
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved