CVE-2020-24559: Trend Micro Apex One

High severity, CVSS 7.8. EPSS: 0.8% chance of exploitation in the next 30 days.

A vulnerability in Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services on macOS may allow an attacker to manipulate a certain binary to load and run a script from a user-writable folder, which then would allow them to execute arbitrary code as root. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

Affected products

  • Trend Micro Apex One: version 2019 only; version saas only
  • Trend Micro OfficeScan: version xg only
  • Trend Micro Worry-Free Business Security: version 10.0 only
  • Trend Micro Worry-Free Business Security Services: affected versions not specified

Published 2020-09-01. Last modified 2026-06-17.