Executive brief
Trend Micro OfficeScan contains a directory traversal vulnerability that allows an authenticated attacker to extract files from an arbitrary zip file to a specific folder on the server. This can lead to remote code execution (RCE) under the context of the web service account.
Affected products
- Trend Micro OfficeScan 11.0, XG (12.0)
Timeline
- 2019-10-28: disclosed: NVD Published Date
- 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: advisory: Publication date of the advisory provided in the source text