{"id":"CVE-2020-24557","vendor_project":"Trend Micro","product":"Apex One, OfficeScan, and Worry-Free Business Security","vulnerability_name":"Trend Micro Multiple Products Improper Access Control Vulnerability","date_added":"2021-11-03","due_date":"2022-05-03","known_ransomware_use":"Unknown","short_description":"Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function, and attain privilege escalation.","required_action":"Apply updates per vendor instructions.","cvss_version":"3.1","cvss_severity":"HIGH","cvss_vector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","nvd_published":"2020-09-01","nvd_status":"Analyzed","epss":0.02666,"epss_percentile":0.85098,"cvss_score":7.8,"days_published_to_kev":428,"source":"https://data.cybermax-tools.workers.dev/cve/CVE-2020-24557","by":"CyberMax"}