Junglewise Threat Intelligence

CVE-2020-8599: Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability

CVE-2020-8599 · Severity: critical · CVSS 9.8 · Exploited in the wild · Published 2021-11-03

Technologies: Trend Micro Officescan. Vendors: Trend Micro.

Executive brief

Trend Micro Apex One and OfficeScan server contain a vulnerable EXE file that allows a remote, unauthenticated attacker to write arbitrary data to an arbitrary path. This vulnerability can be leveraged to bypass ROOT login and gain unauthorized access to the system.

Affected products

  • Trend Micro Apex One 2019
  • Trend Micro OfficeScan XG
  • Trend Micro OfficeScan XG SP1

Timeline

  • 2020-03-17: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: advisory: Publication date of the provided advisory report

Related threats