← Vulnerability feed

Vulnerability record · CVE-2020-15602 · published 15 July 2020

CVE-2020-15602: Trendmicro antivirus\+ 2020 untrusted search path vulnerability

Trendmicro · Antivirus\+ 2020

An untrusted search path remote code execution (RCE) vulnerability in the Trend Micro Secuity 2020 (v16.0.0.1146 and below) consumer family of products could allow an attacker to run arbitrary code on a vulnerable system. As the Trend Micro installer tries to load DLL files from its current directory, an arbitrary DLL could also be loaded with the same privileges as the installer if run as Administrator. User interaction is required to exploit the vulnerbaility in that the target must open a malicious directory or device.

7.8 CVSS 3.1 High EPSS 1.0% · top 38.2% CWE-426 · Untrusted search path
7.8CVSS 3.1 base score, v2 6.9
1.0%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

An untrusted search path remote code execution (RCE) vulnerability in the Trend Micro Secuity 2020 (v16.0.0.1146 and below) consumer family of products could allow an attacker to run arbitrary code on a vulnerable system. As the Trend Micro installer tries to load DLL files from its current directory, an arbitrary DLL could also be loaded with the same privileges as the installer if run as Administrator. User interaction is required to exploit the vulnerbaility in that the target must open a malicious directory or device.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-15602 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-18190Trendmicro antivirus\+ security 2020 null pointer dereference vulnerabilityTrend Micro Security (Consumer) 2020 (v16.x) is affected by a vulnerability in where null pointer dereference errors result in the crash of applicati…EPSS 2.7%7.8CVE-2021-36744Trendmicro maximum security 2019 link following vulnerabilityTrend Micro Security (Consumer) 2021 and 2020 are vulnerable to a directory junction vulnerability which could allow an attacker to exploit the syste…EPSS 0.47%7.8CVE-2020-27696Trendmicro antivirus\+ security 2020 vulnerabilityTrend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a specific Windows system d…EPSS 0.47%7.8CVE-2020-27697Trendmicro antivirus\+ security 2020 link following vulnerabilityTrend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a malicious DLL in a non-pr…EPSS 0.57%7.8CVE-2020-27695Trendmicro antivirus\+ security 2020 untrusted search path vulnerabilityTrend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a malicious DLL in a local …EPSS 0.47%7.8CVE-2019-20357Trendmicro antivirus \+ security 2019 unquoted search path vulnerabilityA Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which c…EPSS 0.73%7.8CVE-2019-15628Trendmicro antivirus \+ security 2020 untrusted search path vulnerabilityTrend Micro Security (Consumer) 2020 (v16.0.1221 and below) is affected by a DLL hijacking vulnerability that could allow an attacker to use a specif…EPSS 0.52%7.5CVE-2020-15603Trendmicro antivirus\+ 2020 out-of-bounds read vulnerabilityAn invalid memory read vulnerability in a Trend Micro Secuity 2020 (v16.0.0.1302 and below) consumer family of products' driver could allow an attack…EPSS 1.2%

Source: NIST National Vulnerability Database (record CVE-2020-15602), CISA KEV, FIRST EPSS (scores of 2026-10-01). This page is refreshed as NVD updates the record.