Executive brief
Trend Micro Apex One and OfficeScan server contain a vulnerable EXE file that allows a remote, unauthenticated attacker to write arbitrary data to an arbitrary path. This vulnerability can be leveraged to bypass ROOT login and gain unauthorized access to the system.
Affected products
- Trend Micro Apex One 2019
- Trend Micro OfficeScan XG
- Trend Micro OfficeScan XG SP1
Timeline
- 2020-03-17: disclosed: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: advisory: Publication date of the provided advisory report