Vulnerabilities > Trendmicro > Maximum Security 2019 > High

DATE CVE VULNERABILITY TITLE RISK
2021-09-06 CVE-2021-36744 Link Following vulnerability in Trendmicro products
Trend Micro Security (Consumer) 2021 and 2020 are vulnerable to a directory junction vulnerability which could allow an attacker to exploit the system to escalate privileges and create a denial of service.
local
low complexity
trendmicro CWE-59
7.8
2020-09-24 CVE-2020-24560 Improper Certificate Validation vulnerability in Trendmicro products
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of the expected one.
network
low complexity
trendmicro CWE-295
7.5
2020-09-24 CVE-2020-15604 Download of Code Without Integrity Check vulnerability in Trendmicro products
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of the expected one.
network
low complexity
trendmicro CWE-494
7.5
2020-01-18 CVE-2019-20357 Unquoted Search Path or Element vulnerability in Trendmicro products
A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious program to escalate privileges and attain persistence on a vulnerable system.
local
low complexity
trendmicro CWE-428
7.8
2019-08-21 CVE-2019-14686 Uncontrolled Search Path Element vulnerability in Trendmicro products
A DLL hijacking vulnerability exists in the Trend Micro Security's 2019 consumer family of products (v15) Folder Shield component and the standalone Trend Micro Ransom Buster (1.0) tool in which, if exploited, would allow an attacker to load a malicious DLL, leading to elevated privileges.
local
low complexity
trendmicro CWE-427
7.8
2019-08-21 CVE-2019-14685 Unquoted Search Path or Element vulnerability in Trendmicro products
A local privilege escalation vulnerability exists in Trend Micro Security 2019 (v15.0) in which, if exploited, would allow an attacker to manipulate a specific product feature to load a malicious service.
local
low complexity
trendmicro CWE-428
7.8