Vulnerability CVE-2019-20358


Published: 2020-01-30   Modified: 2020-01-31

Description:
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed. Another attack vector similar to CVE-2019-9491 was idenitfied and resolved in version 1.62.0.1228 of the tool.

See advisories in our WLB2 database:
Topic
Author
Date
Med.
TrendMicro Anti-Threat Toolkit Improper Fix
Stefan Kanthak
01.02.2020

Type:

CWE-20

(Improper Input Validation)

CVSS2 => (AV:N/AC:H/Au:N/C:P/I:P/A:P)

CVSS Base Score
Impact Subscore
Exploitability Subscore
5.1/10
6.4/10
4.9/10
Exploit range
Attack complexity
Authentication
Remote
High
No required
Confidentiality impact
Integrity impact
Availability impact
Partial
Partial
Partial

 References:
http://seclists.org/fulldisclosure/2020/Jan/50
https://seclists.org/bugtraq/2020/Jan/55
https://success.trendmicro.com/solution/000149878

Copyright 2024, cxsecurity.com

 

Back to Top