Remote Code Execution Vulnerability in Trend Micro Apex One and OfficeScan
CVE-2020-8598
9.8CRITICAL
Key Information:
- Vendor
- Trend Micro
- Vendor
- CVE Published:
- 18 March 2020
Summary
A remote code execution vulnerability exists in the server components of Trend Micro's security products, including Apex One and OfficeScan. This flaw is due to a vulnerable service DLL file that enables attackers to gain SYSTEM level privileges on affected systems. Notably, this vulnerability does not require authentication for exploitation, heightening the risk for users who do not promptly apply available security updates. Deploying protective measures and keeping software up-to-date is essential to mitigate this risk.
Affected Version(s)
Trend Micro OfficeScan, Trend Micro Apex One, Trend Micro Worry-Free Business Security (WFBS) OfficeScan XG (12.0), Apex One 2019 (14.0), WFBS 9.0, 9.5 and 10.0
References
CVSS V3.1
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved