CVE-2020-27014
Description
Trend Micro Antivirus for Mac 2020 (Consumer) contains a race condition vulnerability in the Web Threat Protection Blocklist component, that if exploited, could allow an attacker to case a kernel panic or crash.\n\n\r\nAn attacker must first obtain the ability to execute high-privileged code on the target system in order to exploit this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Race condition in Trend Micro Antivirus for Mac 2020 allows local attackers to cause a kernel panic or crash, requiring high-privileged code execution first.
Vulnerability
The vulnerability is a race condition in the Web Threat Protection Blocklist component of Trend Micro Antivirus for Mac 2020 (v10.x and below). Specifically, it resides in the KERedirect kext due to lack of proper locking when performing operations on an object [1]. Affected versions: Antivirus for Mac 2020 (v10.x) and below [2].
Exploitation
An attacker must first obtain the ability to execute high-privileged code on the target system [2]. Then, the attacker can trigger a time-of-check time-of-use (TOCTOU) race condition to exploit the lack of proper locking in the kext [1]. This requires precise timing to win the race.
Impact
Successful exploitation can cause a kernel panic or crash, leading to denial of service. Additionally, due to the kernel-level nature, an attacker could potentially escalate privileges and execute code in the kernel context [1]. CVSS score 8.2 (high) with vector AV:L/AC:L/PR:H/UI:N/S:C/C:H/I:H/A:H [1].
Mitigation
Trend Micro released patches via ActiveUpdate for versions 2020 v10.5 and v10.0 [2]. Customers with at least v10.0 should already have the fix. Users on v9.0 or below should upgrade to the latest version (2021 v11) [2]. No workaround is provided.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2(expand)+ 1 more
- (no CPE)
- (no CPE)range: 2020 (v10.x) and below
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- helpcenter.trendmicro.com/en-us/article/TMKA-09974mitrex_refsource_MISC
- www.zerodayinitiative.com/advisories/ZDI-20-1285/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.