Junglewise Threat Intelligence

CVE-2020-8468: Trend Micro Multiple Products Content Validation Escape Vulnerability

CVE-2020-8468 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Trend Micro Officescan. Vendors: Trend Micro.

Executive brief

Trend Micro Apex One, OfficeScan, and Worry-Free Business Security agents are vulnerable to a content validation escape. This flaw allows an authenticated attacker to bypass validation mechanisms and manipulate specific agent client components.

Affected products

  • Trend Micro Apex One 2019
  • Trend Micro OfficeScan XG
  • Trend Micro Worry-Free Business Security 9.0, 9.5, 10.0

Timeline

  • 2020-03-17: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Confirmed exploited in the wild per CISA KEV entry

Related threats