Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2020-8607


An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver could allow an attacker in user-mode with administrator permissions to abuse the driver to modify a kernel address that may cause a system crash or potentially lead to code execution in kernel mode. An attacker must already have obtained administrator access on the target machine (either legitimately or via a separate unrelated attack) to exploit this vulnerability.


Security Impact Summary

This vulnerability carries a MEDIUM severity rating with a CVSS v3.1 score of 6.7, requiring local system access to exploit with relatively low complexity without requiring user interaction . The vulnerability impacts confidentiality (data exposure), integrity (unauthorized modifications), and availability (service disruption) for affected systems. Impacting 13 products from trendmicro, from trendmicro, from trendmicro and 10 others, organizations running these solutions should prioritize assessment and patching.

Historical Context

Reported in 2020, this vulnerability emerged during an era marked by increased sophistication in supply chain attacks, cloud infrastructure vulnerabilities, and software-as-a-service (SaaS) security challenges. Security practices during this period emphasized zero-trust architectures, container security, and API protection.


Published

2020-08-05T14:15:13.530

Last Modified

2024-11-21T05:39:07.050

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 6.7 (MEDIUM)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application trendmicro antivirus_toolkit < 1.62.1240 Yes
Application trendmicro apex_one 2019 Yes
Application trendmicro apex_one saas Yes
Application trendmicro deep_security 9.6 Yes
Application trendmicro deep_security 10.0 Yes
Application trendmicro deep_security 11.0 Yes
Application trendmicro deep_security 12.0 Yes
Application trendmicro officescan xg Yes
Application trendmicro officescan_business_security 9.0 Yes
Application trendmicro officescan_business_security 9.5 Yes
Application trendmicro officescan_business_security 10.0 Yes
Application trendmicro officescan_business_security_service - Yes
Application trendmicro officescan_cloud 15 Yes
Application trendmicro officescan_cloud 16.0 Yes
Application trendmicro online_scan 8.0 Yes
Application trendmicro portable_security 2.0 Yes
Application trendmicro portable_security 3.0 Yes
Application trendmicro rootkit_buster 2.2 Yes
Application trendmicro safe_lock - Yes
Application trendmicro safe_lock 2.0 Yes
Application trendmicro serverprotect 5.8 Yes
Application trendmicro serverprotect 5.8 Yes
Application trendmicro serverprotect 5.8 Yes
Application trendmicro serverprotect 6.0 Yes
Operating System microsoft windows - No

References

How SecUtils Interprets This CVE

SecUtils normalizes and enriches National Vulnerability Database (NVD) records by standardizing vendor and product identifiers, aggregating vulnerability metadata from both NVD and MITRE sources, and providing structured context for security teams. For trendmicro's affected products, we extract Common Platform Enumeration (CPE) data, Common Weakness Enumeration (CWE) classifications, CVSS severity metrics, and reference data to enable rapid vulnerability prioritization and asset correlation. This record contains no exploit code, proof-of-concept instructions, or attack methodologies—only defensive intelligence necessary for patch management, risk assessment, and security operations.