CVE-2020-24560
Summary
| CVE | CVE-2020-24560 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2020-09-24 02:15:00 UTC |
| Updated | 2020-09-30 14:08:00 UTC |
| Description | An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of the expected one. CWE-295: Improper server certificate verification in the communication with the update server. |
Risk And Classification
Problem Types: CWE-295
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Operating System | Microsoft | Windows | - | All | All | All |
| Operating System | Microsoft | Windows | - | All | All | All |
| Application | Trendmicro | Antivirus 2019 | All | All | All | All |
| Application | Trendmicro | Internet Security 2019 | All | All | All | All |
| Application | Trendmicro | Maximum Security 2019 | All | All | All | All |
| Application | Trendmicro | Officescan Cloud | 15 | All | All | All |
| Application | Trendmicro | Officescan Cloud | 15 | All | All | All |
| Application | Trendmicro | Premium Security 2019 | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| JVN#60093979: Multiple vulnerabilities in Active Update function implemented in multiple Trend Micro products | MISC | jvn.jp | Third Party Advisory |
| アラート/アドバイザリ:ウイルスバスター クラウドの脆弱性について(CVE-2020-15604/CVE-2020-24560) · Trend Micro for Home | MISC | helpcenter.trendmicro.com | Vendor Advisory |
| JVN#60093979: ウイルスバスター クラウド (Windows版) に実装された Active Update 機能における複数の脆弱性 | MISC | jvn.jp | Third Party Advisory |
| Security Bulletin: Trend Micro Security 2019 (Consumer) Incomplete SSL Server Certification Validation Vulnerability · Trend Micro for Home | MISC | helpcenter.trendmicro.com | Vendor Advisory |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.