Web Server API Flaw in Trend Micro Antivirus for Mac 2020
CVE-2020-27013

4.4MEDIUM

Key Information:

Vendor
CVE Published:
14 October 2020

Summary

Trend Micro Antivirus for Mac 2020 features a security weakness stemming from its improper handling of a web server API. This flaw permits an attacker with the ability to execute low-privileged code on a targeted Mac device to read and manipulate sensitive product and user data. By exploiting this vulnerability, an attacker could potentially gain access to critical information, which poses significant risks to user security and privacy.

Affected Version(s)

Trend Micro Antivirus for Mac (Consumer) 2020 (v10.x)

References

CVSS V3.1

Score:
4.4
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.