CVE-2020-24560: Trend Micro Antivirus+ 2019
High severity, CVSS 7.5. EPSS: 1.8% chance of exploitation in the next 30 days.
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of the expected one. CWE-295: Improper server certificate verification in the communication with the update server.
Affected products
- Trend Micro Antivirus+ 2019: up to and including 15.0
- Trend Micro Internet Security 2019: up to and including 15.0
- Trend Micro Maximum Security 2019: up to and including 15.0
- Trend Micro OfficeScan Cloud: version 15 only
- Trend Micro Premium Security 2019: up to and including 15.0
Published 2020-09-24. Last modified 2026-06-17.