#VU46136 Improper access control in Apex One - CVE-2020-24557
Published: August 31, 2020 / Updated: April 22, 2021
Apex One
Trend Micro
Description
The vulnerability allows a local user to gain unauthorized access to otherwise restricted functionality.
The vulnerability exists due to improper access restrictions within the ApexOne Security Agent. A local user can manipulate a particular product folder to disable the security temporarily and gain elevated privileges on the target system.