CVE-2020-15603

Severity CVSS v4.0:
Pending analysis
Type:
CWE-125 Out-of-bounds Read
Publication date:
15/07/2020
Last modified:
22/07/2020

Description

An invalid memory read vulnerability in a Trend Micro Secuity 2020 (v16.0.0.1302 and below) consumer family of products' driver could allow an attacker to manipulate the specific driver to do a system call operation with an invalid address, resulting in a potential system crash.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:trendmicro:antivirus\+_2020:*:*:*:*:*:*:*:* 16.0.1302 (including)
cpe:2.3:a:trendmicro:internet_security_2020:*:*:*:*:*:*:*:* 16.0.1302 (including)
cpe:2.3:a:trendmicro:maximum_security_2020:*:*:*:*:*:*:*:* 16.0.1302 (including)
cpe:2.3:a:trendmicro:premium_security_2020:*:*:*:*:*:*:*:* 16.0.1302 (including)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*


References to Advisories, Solutions, and Tools