Web Server API Flaw in Trend Micro Antivirus for Mac 2020
CVE-2020-27013
4.4MEDIUM
Key Information:
- Vendor
- Trend Micro
- Vendor
- CVE Published:
- 14 October 2020
Summary
Trend Micro Antivirus for Mac 2020 features a security weakness stemming from its improper handling of a web server API. This flaw permits an attacker with the ability to execute low-privileged code on a targeted Mac device to read and manipulate sensitive product and user data. By exploiting this vulnerability, an attacker could potentially gain access to critical information, which poses significant risks to user security and privacy.
Affected Version(s)
Trend Micro Antivirus for Mac (Consumer) 2020 (v10.x)
References
CVSS V3.1
Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved