LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-24557: Trend Micro Multiple Products Improper Access Control Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-24557 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows contain an improper access control vulnerability that may allow an attacker to manipulate a particular product…

CVE-2020-24557 is an improper access control vulnerability in Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Microsoft Windows. An attacker who can manipulate a particular product folder may temporarily disable the security software, abuse a specific Windows function, and escalate privileges. For IT and security teams running these endpoint products, the issue matters because it can undermine the very controls meant to protect the host and open a path to higher privileges on the system.

Public detail is limited to the CISA description and the vendor products named above. Confirm exact affected builds, fixed versions, and deployment guidance directly against the Trend Micro advisory before acting.

How it works

The flaw is an improper access control weakness in the named Trend Micro products. In practical terms, the software does not sufficiently restrict what can be done to a particular product folder on the Windows host. An attacker who already has some level of access on the machine may manipulate that folder in a way that temporarily disables the security product. With protection weakened or off, the attacker can then abuse a specific Windows function to escalate privileges.

This is a local privilege-escalation style issue rather than a remote unauthenticated wormable flaw. Exploitation depends on the attacker already being able to interact with the affected product’s folder structure on the endpoint. Exact mechanics, prerequisites, and any required user interaction are not fully detailed in the public summary; treat the CISA description as the authoritative high-level picture and verify technical specifics in the vendor advisory.

Am I affected? How to find it in your systems

These products are typically deployed as endpoint security agents on Windows workstations and servers—Apex One and OfficeScan in enterprise environments, Worry-Free Business Security more often in smaller or mid-size deployments. Inventory every Windows host that runs a Trend Micro agent from this product family.

If you cannot confirm the exact build, assume the host may be in scope until the vendor advisory rules it out.

How to remediate

Patch first. Apply the updates Trend Micro released for this vulnerability, following the vendor’s instructions exactly as stated in the advisory. CISA’s required action is to apply updates per vendor instructions; that remains the primary fix.

As general hardening for this class of issue, ensure endpoint agents run with least privilege where the product allows it, restrict who can write to security-product directories, and keep host-based application control or tamper-protection features enabled per vendor guidance.

If you can't patch immediately

If you cannot apply the vendor update at once, reduce risk with compensating controls until you can.

These steps do not replace the vendor update; they only buy time.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities on endpoints can lead to full host compromise and subsequent data theft or ransomware staging, even when ransomware use of this specific CVE is not documented. If you have evidence of exploitation or unexplained agent disablement on vulnerable systems, follow your incident-response process: isolate affected hosts, preserve logs, rotate credentials that may have been exposed, and assess what data the elevated attacker could have reached. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data to see whether your accounts already appear in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedTrend Micro · Apex One, OfficeScan, and Worry-Free Business Security
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities