Arbitrary File Deletion Vulnerability in Trend Micro Security Products
CVE-2020-25775

6.3MEDIUM

Key Information:

Vendor
CVE Published:
29 September 2020

Summary

The Trend Micro Security 2020 (v16) product family is exposed to a security race condition that permits unprivileged users to exploit the secure erase functionality, potentially leading to unauthorized file deletions. This vulnerability can be manipulated to delete files that are typically protected due to their higher privilege status. The implications could severely compromise the integrity of data management within the affected systems.

Affected Version(s)

Trend Micro Security (Consumer) 2020 (v16)

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.