Homograph Attack Vulnerability in Trend Micro Antivirus for Mac
CVE-2020-25779

3.3LOW

Key Information:

Vendor
CVE Published:
13 October 2020

Summary

Trend Micro Antivirus for Mac 2020 has a vulnerability that can be exploited through an Internationalized Domain Name (IDN) homograph attack. An attacker can manipulate domain names using Puny-code to make malicious websites appear legitimate and thus add them to the approved websites list of Trend Micro Antivirus. This allows the attacker to bypass the web threat protection features of the software, potentially exposing users to security risks when visiting these malicious sites.

Affected Version(s)

Trend Micro Antivirus for Mac (Consumer) 2020 (v10.x)

References

CVSS V3.1

Score:
3.3
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.