CVE-2020-8467: high-severity vulnerability in Trend Micro OfficeScan, Trend Micro Apex One
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA.
Apply updates per vendor instructions.
A migration tool in Trend Micro Apex One (2019) and OfficeScan XG allows authenticated attackers to run arbitrary code on the system. This is dangerous because an authenticated user could take full control of the protected computer.
The migration tool component fails to properly validate or sanitize user-supplied input, enabling authenticated remote code execution (RCE). An attacker with valid credentials can exploit this to execute arbitrary commands with the privileges of the affected application, potentially leading to complete system compromise.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.