Incomplete SSL Server Certification Validation in Trend Micro Security Products
CVE-2020-24560
Key Information:
- Vendor
Trend Micro
- Vendor
- CVE Published:
- 24 September 2020
What is CVE-2020-24560?
An incomplete SSL server certification validation vulnerability exists in Trend Micro Security 2019 (v15) that can potentially be exploited by attackers. This flaw allows attackers to combine it with other tactics to mislead users into downloading malicious updates rather than legitimate ones. The issue stems from improper verification of the server certificate during communications with the update server, which poses significant risks to users who may receive harmful updates instead of expected security patches. Ensuring proper validation of server certificates is crucial to protect against such vulnerabilities.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Trend Micro Security (Consumer) 2019 (v15)
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved