← Back to browse · API

CVE-2020-24557

Severity
HIGH
CVSS
7.8
EPSS
0.02639
Risk score
57.12
CISA KEV
Yes
PoC
No
Published
2021-11-03
Modified
2021-11-03
First seen
2026-08-07
Aliases
EUVD-2020-17276, GHSA-RF37-CMCM-645M
Products
Trend Micro, Inc.:Trend Micro Worry-Free Business Security 10.0 SP1, Trend Micro:Apex One, OfficeScan, and Worry-Free Business Security, Trend Micro:Trend Micro Apex One 2009 (on premise), SaaS
Sources
euvd EUVD-2020-17276
cisa.gov CVE-2020-24557

Description

Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function, and attain privilege escalation.

References