CVE-2020-27697

EUVD-2020-20201
Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a malicious DLL in a non-protected location with high privileges (symlink attack) which can lead to obtaining administrative privileges during the installation of the product.
Link Following
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 15%
Affected Products (NVD)
VendorProductVersion
trendmicroantivirus\+_security_2020
𝑥
≤ 16.0
trendmicrointernet_security_2020
𝑥
≤ 16.0
trendmicromaximum_security_2020
𝑥
≤ 16.0
trendmicropremium_security_2020
𝑥
≤ 16.0
𝑥
= Vulnerable software versions