Junglewise Threat Intelligence

CVE-2019-18187: Trend Micro OfficeScan Directory Traversal Vulnerability

CVE-2019-18187 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Trend Micro Officescan. Vendors: Trend Micro.

Executive brief

Trend Micro OfficeScan contains a directory traversal vulnerability that allows an authenticated attacker to extract files from an arbitrary zip file to a specific folder on the server. This can lead to remote code execution (RCE) under the context of the web service account.

Affected products

  • Trend Micro OfficeScan 11.0, XG (12.0)

Timeline

  • 2019-10-28: disclosed: NVD Published Date
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: advisory: Publication date of the advisory provided in the source text

Related threats