CVE-2020-25775
Description
The Trend Micro Security 2020 (v16) consumer family of products is vulnerable to a security race condition arbitrary file deletion vulnerability that could allow an unprivileged user to manipulate the product's secure erase feature to delete files with a higher set of privileges.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A race condition in Trend Micro Security 2020's Secure Erase feature allows low-privileged users to delete arbitrary files as SYSTEM.
Vulnerability
The vulnerability resides in the Secure Erase feature of Trend Micro Security 2020 (v16) consumer products, including Premium Security, Maximum Security, Internet Security, and Antivirus+. It is a race condition caused by improper validation of a user-supplied link before file operations. Affected versions are Trend Micro Security 2020 (v16) and below. [1][2]
Exploitation
An attacker must first obtain the ability to execute low-privileged code on the target system. The exploit involves manipulating the Secure Erase feature's race window to delete arbitrary files. The specific flaw is the lack of proper validation of a user-supplied link, which the attacker can control. [1]
Impact
Successful exploitation allows an attacker to delete arbitrary files in the context of the SYSTEM account. This results in a high impact on integrity (file deletion) but no confidentiality impact. The CVSSv3 score is 5.3 (AV:L/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:H). [1][2]
Mitigation
Trend Micro addressed this vulnerability via a patch delivered through the product's automatic ActiveUpdate feature for all versions at or above Trend Micro Security 2020 (v16). Customers who are up-to-date with v16 already have the fix. Users on version 2019 (v15) or below should upgrade to v16 or v17. No active exploitation has been reported. [2]
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: v16
- Range: 2020 (v16)
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- helpcenter.trendmicro.com/en-us/article/TMKA-09909mitrex_refsource_MISC
- www.zerodayinitiative.com/advisories/ZDI-20-1227/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.