CVE-2020-8599: critical vulnerability in Trend Micro OfficeScan, Trend Micro Apex One
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA.
Apply updates per vendor instructions.
Trend Micro Apex One and OfficeScan XG servers have a flaw that lets attackers write files anywhere on the system without needing to log in. This can allow them to bypass security controls and take over the computer.
A vulnerable executable in Trend Micro Apex One (2019) and OfficeScan XG permits unauthenticated remote attackers to write arbitrary files to arbitrary paths, enabling privilege escalation and ROOT login bypass. The vulnerability requires network access to the affected server but no credentials, resulting in complete system compromise.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.