CVE-2020-8607: Trend Micro Antivirus Toolkit
Medium severity, CVSS 6.7. EPSS: 0.6% chance of exploitation in the next 30 days.
An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver could allow an attacker in user-mode with administrator permissions to abuse the driver to modify a kernel address that may cause a system crash or potentially lead to code execution in kernel mode. An attacker must already have obtained administrator access on the target machine (either legitimately or via a separate unrelated attack) to exploit this vulnerability.
Affected products
- Trend Micro Antivirus Toolkit: before 1.62.1240 (fixed in 1.62.1240)
- Trend Micro Apex One: version 2019 only; version saas only
- Trend Micro Deep Security: version 9.6 only; version 10.0 only; version 11.0 only; version 12.0 only
- Trend Micro OfficeScan: version xg only
- Trend Micro OfficeScan Business Security: version 9.0 only; version 9.5 only; version 10.0 only
- Trend Micro OfficeScan Business Security Service: affected versions not specified
- Trend Micro OfficeScan Cloud: version 15 only; version 16.0 only
- Trend Micro Online Scan: version 8.0 only
- Trend Micro Portable Security: version 2.0 only; version 3.0 only
- Trend Micro Rootkit Buster: version 2.2 only
- Trend Micro Safe Lock: affected versions not specified; version 2.0 only
- Trend Micro Serverprotect: version 5.8 only; version 6.0 only
Published 2020-08-05. Last modified 2026-06-17.