CVE-2020-27697: Trend Micro Antivirus+ Security 2020

High severity, CVSS 7.8. EPSS: 0.6% chance of exploitation in the next 30 days.

Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a malicious DLL in a non-protected location with high privileges (symlink attack) which can lead to obtaining administrative privileges during the installation of the product.

Affected products

  • Trend Micro Antivirus+ Security 2020: up to and including 16.0
  • Trend Micro Internet Security 2020: up to and including 16.0
  • Trend Micro Maximum Security 2020: up to and including 16.0
  • Trend Micro Premium Security 2020: up to and including 16.0

Published 2020-11-18. Last modified 2026-06-17.