CVE-2020-24558: Trend Micro Apex One

High severity, CVSS 7.1. EPSS: 0.6% chance of exploitation in the next 30 days.

A vulnerability in an Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services dll may allow an attacker to manipulate it to cause an out-of-bounds read that crashes multiple processes in the product. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

Affected products

  • Trend Micro Apex One: version 2019 only; version saas only
  • Trend Micro Worry-Free Business Security: version 10.0 only
  • Trend Micro Worry-Free Business Security Services: affected versions not specified

Published 2020-09-01. Last modified 2026-06-17.