Trendmicro Internet Security 2019 vulnerabilities

7 known vulnerabilities affecting trendmicro/internet_security_2019.

Total CVEs
7
CISA KEV
0
Public exploits
2
Exploited in wild
0
Severity breakdown
HIGH5MEDIUM2

Vulnerabilities

Page 1 of 1
CVE-2020-15604HIGHCVSS 7.5≤ 15.02020-09-24
CVE-2020-15604 [HIGH] CWE-295 CVE-2020-15604: An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v1 An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of the expected one. CWE-494: Update files are not properly verified.
nvd
CVE-2020-24560HIGHCVSS 7.5≤ 15.02020-09-24
CVE-2020-24560 [HIGH] CWE-295 CVE-2020-24560: An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v1 An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of the expected one. CWE-295: Improper server certificate verification in th
nvd
CVE-2019-19694MEDIUMCVSS 4.7≤ 15.0.0.11632020-02-20
CVE-2019-19694 [MEDIUM] CVE-2019-19694: The Trend Micro Security 2019 (15.0.0.1163 and below) consumer family of products is vulnerable to a The Trend Micro Security 2019 (15.0.0.1163 and below) consumer family of products is vulnerable to a denial of service (DoS) attack in which a malicious actor could manipulate a key file at a certain time during the system startup process to disable the product's malware protection functions or the entire product completely..
nvd
CVE-2019-20357HIGHCVSS 7.8PoCv15.02020-01-18
CVE-2019-20357 [HIGH] CWE-428 CVE-2019-20357: A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 an A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious program to escalate privileges and attain persistence on a vulnerable system.
nvd
CVE-2019-19697MEDIUMCVSS 6.7PoCv15.02020-01-18
CVE-2019-19697 [MEDIUM] CVE-2019-19697: An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer fam An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products which could allow an attacker to gain elevated privileges and tamper with protected services by disabling or otherwise preventing them to start. An attacker must already have administrator privileges on the target machine in order to exploit t
nvd
CVE-2019-14686HIGHCVSS 7.8v15.02019-08-21
CVE-2019-14686 [HIGH] CWE-427 CVE-2019-14686: A DLL hijacking vulnerability exists in the Trend Micro Security's 2019 consumer family of products A DLL hijacking vulnerability exists in the Trend Micro Security's 2019 consumer family of products (v15) Folder Shield component and the standalone Trend Micro Ransom Buster (1.0) tool in which, if exploited, would allow an attacker to load a malicious DLL, leading to elevated privileges.
nvd
CVE-2019-14685HIGHCVSS 7.8v15.02019-08-21
CVE-2019-14685 [HIGH] CWE-428 CVE-2019-14685: A local privilege escalation vulnerability exists in Trend Micro Security 2019 (v15.0) in which, if A local privilege escalation vulnerability exists in Trend Micro Security 2019 (v15.0) in which, if exploited, would allow an attacker to manipulate a specific product feature to load a malicious service.
nvd