CVE-2019-20357
Severity CVSS v4.0:
Pending analysis
Type:
CWE-428
Unquoted Search Path or Element
Publication date:
18/01/2020
Last modified:
17/06/2026
Description
A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious program to escalate privileges and attain persistence on a vulnerable system.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
7.20
Severity 2.0
HIGH
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:trendmicro:antivirus_\+_security_2019:15.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trendmicro:antivirus_\+_security_2020:16.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trendmicro:internet_security_2019:15.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trendmicro:internet_security_2020:16.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trendmicro:maximum_security_2019:15.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trendmicro:maximum_security_2020:16.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trendmicro:premium_security_2019:15.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trendmicro:premium_security_2020:16.0:*:*:*:*:*:*:* | ||
| cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page
References to Advisories, Solutions, and Tools
- http://hyp3rlinx.altervista.org/advisories/TREND-MICRO-SECURITY-CONSUMER-PERSISTENT-ARBITRARY-CODE-EXECUTION.txt
- https://esupport.trendmicro.com/en-us/home/pages/technical-support/1124099.aspx
- https://seclists.org/bugtraq/2020/Jan/28
- http://hyp3rlinx.altervista.org/advisories/TREND-MICRO-SECURITY-CONSUMER-PERSISTENT-ARBITRARY-CODE-EXECUTION.txt
- https://esupport.trendmicro.com/en-us/home/pages/technical-support/1124099.aspx
- https://seclists.org/bugtraq/2020/Jan/28



