Vulnerability Description
Trend Micro Antivirus for Mac 2020 (Consumer) contains a vulnerability in the product that occurs when a webserver is started that implements an API with several properties that can be read and written to allowing the attacker to gather and modify sensitive product and user data. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trendmicro | Antivirus | 2020 |
References
- https://helpcenter.trendmicro.com/en-us/article/TMKA-09950Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-1243/Third Party AdvisoryVDB Entry
- https://helpcenter.trendmicro.com/en-us/article/TMKA-09950Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-20-1243/Third Party AdvisoryVDB Entry
FAQ
What is CVE-2020-27013?
CVE-2020-27013 is a vulnerability with a CVSS score of 4.4 (MEDIUM). Trend Micro Antivirus for Mac 2020 (Consumer) contains a vulnerability in the product that occurs when a webserver is started that implements an API with several properties that can be read and writte...
How severe is CVE-2020-27013?
CVE-2020-27013 has been rated MEDIUM with a CVSS base score of 4.4/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-27013?
Check the references section above for vendor advisories and patch information. Affected products include: Trendmicro Antivirus.