Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2019-20358

Опубликовано: 30 янв. 2020
Источник: nvd
CVSS3: 7.8
CVSS2: 5.1
EPSS Низкий

Описание

Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed. Another attack vector similar to CVE-2019-9491 was idenitfied and resolved in version 1.62.0.1228 of the tool.

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:a:trendmicro:anti-threat_toolkit:*:*:*:*:*:*:*:*
Версия до 1.62.0.1218 (включая)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

EPSS

Процентиль: 88%
0.03625
Низкий

7.8 High

CVSS3

5.1 Medium

CVSS2

Дефекты

CWE-426

Связанные уязвимости

github
больше 3 лет назад

Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed. Another attack vector similar to CVE-2019-9491 was idenitfied and resolved in version 1.62.0.1228 of the tool.

EPSS

Процентиль: 88%
0.03625
Низкий

7.8 High

CVSS3

5.1 Medium

CVSS2

Дефекты

CWE-426