CVE-2020-8599criticalunder attack

CVE-2020-8599: critical vulnerability in Trend Micro OfficeScan, Trend Micro Apex One

Published · Updated

63Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA.

ssvc Actcvss 9.8epss 12%
from disclosure to weapon
Published on NVDMar 18
CISA KEV+595d
exploitation probability
12%top 4% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2022-05-03

Apply updates per vendor instructions.

In short

Trend Micro Apex One and OfficeScan XG servers have a flaw that lets attackers write files anywhere on the system without needing to log in. This can allow them to bypass security controls and take over the computer.

Technical detail

A vulnerable executable in Trend Micro Apex One (2019) and OfficeScan XG permits unauthenticated remote attackers to write arbitrary files to arbitrary paths, enabling privilege escalation and ROOT login bypass. The vulnerability requires network access to the affected server but no credentials, resulting in complete system compromise.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected installations and bypass ROOT login. Authentication is not required to exploit this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Related CVEs — Trend Micro OfficeScan, Trend Micro Apex One

In the same product, most dangerous first.