Vulnerabilities > Trendmicro > High

DATE CVE VULNERABILITY TITLE RISK
2020-05-27 CVE-2020-8606 Improper Authentication vulnerability in Trendmicro Interscan web Security Virtual Appliance 6.5
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to bypass authentication on affected installations of Trend Micro InterScan Web Security Virtual Appliance.
network
low complexity
trendmicro CWE-287
7.5
2020-03-18 CVE-2020-8600 Path Traversal vulnerability in Trendmicro Worry-Free Business Security 10.0/9.0/9.5
Trend Micro Worry-Free Business Security (9.0, 9.5, 10.0) is affected by a directory traversal vulnerability that could allow an attacker to manipulate a key file to bypass authentication.
network
low complexity
trendmicro CWE-22
7.5
2020-01-18 CVE-2019-20357 Improper Input Validation vulnerability in Trendmicro products
A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious program to escalate privileges and attain persistence on a vulnerable system.
local
low complexity
trendmicro CWE-20
7.2
2020-01-18 CVE-2019-19697 Unspecified vulnerability in Trendmicro products
An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products which could allow an attacker to gain elevated privileges and tamper with protected services by disabling or otherwise preventing them to start.
local
low complexity
trendmicro microsoft
7.2
2019-12-18 CVE-2019-19690 Weak Password Requirements vulnerability in Trendmicro Mobile Security 10.3.1/9.8
Trend Micro Mobile Security for Android (Consumer) versions 10.3.1 and below on Android 8.0+ has an issue in which an attacker could bypass the product's App Password Protection feature.
network
low complexity
trendmicro CWE-521
7.5
2019-12-09 CVE-2019-18190 NULL Pointer Dereference vulnerability in Trendmicro products
Trend Micro Security (Consumer) 2020 (v16.x) is affected by a vulnerability in where null pointer dereference errors result in the crash of application, which could potentially lead to possible unsigned code execution under certain circumstances.
network
low complexity
trendmicro CWE-476
7.5
2019-10-21 CVE-2019-9491 Uncontrolled Search Path Element vulnerability in Trendmicro Anti-Threat Toolkit 1.62.0.1218
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed.
local
low complexity
trendmicro CWE-427
7.8
2019-08-21 CVE-2019-14685 Unquoted Search Path or Element vulnerability in Trendmicro products
A local privilege escalation vulnerability exists in Trend Micro Security 2019 (v15.0) in which, if exploited, would allow an attacker to manipulate a specific product feature to load a malicious service.
local
low complexity
trendmicro microsoft CWE-428
7.2
2019-08-20 CVE-2019-14687 Uncontrolled Search Path Element vulnerability in Trendmicro Password Manager 5.0
A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process.
local
low complexity
trendmicro CWE-427
7.8
2018-10-23 CVE-2018-18329 NULL Pointer Dereference vulnerability in Trendmicro products
A KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer) 7.0 (2017) and above could allow a local attacker to escalate privileges on vulnerable installations.
local
low complexity
trendmicro CWE-476
7.2