CVE-2020-24559: Trend Micro Apex One
High severity, CVSS 7.8. EPSS: 0.8% chance of exploitation in the next 30 days.
A vulnerability in Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services on macOS may allow an attacker to manipulate a certain binary to load and run a script from a user-writable folder, which then would allow them to execute arbitrary code as root. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Affected products
- Trend Micro Apex One: version 2019 only; version saas only
- Trend Micro OfficeScan: version xg only
- Trend Micro Worry-Free Business Security: version 10.0 only
- Trend Micro Worry-Free Business Security Services: affected versions not specified
Published 2020-09-01. Last modified 2026-06-17.