CVE-2020-27697

Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a malicious DLL in a non-protected location with high privileges (symlink attack) which can lead to obtaining administrative privileges during the installation of the product.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
trendmicroCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 15%
VendorProductVersion
trendmicroantivirus\+_security_2020
𝑥
≤ 16.0
trendmicrointernet_security_2020
𝑥
≤ 16.0
trendmicromaximum_security_2020
𝑥
≤ 16.0
trendmicropremium_security_2020
𝑥
≤ 16.0
𝑥
= Vulnerable software versions