VYPR
High severity7.8NVD Advisory· Published Sep 1, 2020· Updated Jun 17, 2026

CVE-2020-24556

CVE-2020-24556

Description

A vulnerability in Trend Micro Apex One, OfficeScan XG SP1, Worry-Free Business Security 10 SP1 and Worry-Free Business Security Services on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Please note that version 1909 (OS Build 18363.719) of Microsoft Windows 10 mitigates hard links, but previous versions are affected.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

10
  • cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:*:*:*:*
    • cpe:2.3:a:trendmicro:apex_one:saas:*:*:*:*:*:*:*
    • (no CPE)
  • cpe:2.3:a:trendmicro:worry-free_business_security:10.0:sp1:*:*:*:*:*:*+ 2 more
    • cpe:2.3:a:trendmicro:worry-free_business_security:10.0:sp1:*:*:*:*:*:*
    • (no CPE)
    • (no CPE)range: 10 SP1, Services (SaaS)
  • cpe:2.3:a:trendmicro:worry-free_business_security_services:-:*:*:*:*:*:*:*
  • Trend Micro/Trend Micro Apex Onev5
    Range: 2009 (on premise), SaaS
  • Trend Micro/Trend Micro OfficeScanv5
    Range: XG SP1

Patches

Vulnerability mechanics

References

4

News mentions

0

No linked articles in our index yet.