CVE-2020-25775Race Condition in Antivirus + 2020

CWE-362Race Condition3 documents3 sources
Severity
6.3MEDIUMNVD
EPSS
0.1%
top 80.84%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 29
Latest updateMay 24

Description

The Trend Micro Security 2020 (v16) consumer family of products is vulnerable to a security race condition arbitrary file deletion vulnerability that could allow an unprivileged user to manipulate the product's secure erase feature to delete files with a higher set of privileges.

CVSS vector

CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:H/A:HExploitability: 1.0 | Impact: 5.2

🔴Vulnerability Details

2
GHSA
GHSA-hg9j-r439-gp76: The Trend Micro Security 2020 (v16) consumer family of products is vulnerable to a security race condition arbitrary file deletion vulnerability that2022-05-24
CVEList
CVE-2020-25775: The Trend Micro Security 2020 (v16) consumer family of products is vulnerable to a security race condition arbitrary file deletion vulnerability that2020-09-28
CVE-2020-25775 — Race Condition in Trendmicro | cvebase