Junglewise Threat Intelligence

CVE-2020-8467: Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability

CVE-2020-8467 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Trend Micro Officescan. Vendors: Trend Micro.

Executive brief

A migration tool component in Trend Micro Apex One and OfficeScan contains an unspecified vulnerability that allows authenticated remote attackers to execute arbitrary code. The vulnerability has been observed being exploited in the wild.

Affected products

  • Trend Micro Apex One 2019
  • Trend Micro OfficeScan XG
  • Trend Micro OfficeScan XG SP1

Timeline

  • 2020-03-17: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog

Related threats