Content Validation Escape Vulnerability in Trend Micro Products
CVE-2020-8468
Key Information:
- Vendor
- Trend Micro
- Vendor
- CVE Published:
- 18 March 2020
Badges
Summary
Trend Micro Apex One (2019), OfficeScan XG, and Worry-Free Business Security (versions 9.0, 9.5, and 10.0) are susceptible to a content validation escape vulnerability. This flaw could allow an authenticated attacker to manipulate specific components within the agent client, leading to potential unauthorized actions or data exposure. Organizations utilizing these products should ensure that they maintain up-to-date security measures to mitigate risks associated with this vulnerability.
CISA Reported
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply updates per vendor instructions.
Affected Version(s)
Trend Micro OfficeScan, Trend Micro Apex One, Trend Micro Worry-Free Business Security (WFBS) OfficeScan XG (12.0), Apex One 2019 (14.0), WFBS 9.0, 9.5 and 10.0
References
CVSS V3.1
Timeline
- 👾
Exploit known to exist
- 🦅
CISA Reported
Vulnerability published
Vulnerability Reserved