ZeroHour

CVE-2019-18187

KEVlarge

Directory Traversal RCE in Trend Micro OfficeScan

CISA: Trend Micro OfficeScan Directory Traversal Vulnerability

CVSS 3.1
7.5 high
EPSS
25%p98
Published
()
KEV added
AI analysis

Trend Micro OfficeScan contains a directory traversal flaw (CWE-22) in its handling of ZIP archives: when a zip file is extracted to a designated folder on the OfficeScan server, archive entries can escape that folder, allowing an attacker to place files at exploitable locations and achieve remote code execution. The flaw is triggered by getting the server to extract an attacker-influenced ZIP archive into the specific folder on the OfficeScan server. Successful exploitation yields arbitrary code execution on the OfficeScan management server, which typically holds broad control over the managed endpoint fleet and can serve as a foothold for lateral movement. Any organization running an on-premises Trend Micro OfficeScan deployment is affected; the source data does not specify affected version ranges. The vulnerability was added to the CISA KEV catalog on 2021-11-03 (indicating observed exploitation, with ransomware use unknown), and EPSS assigns a 25.1% probability of exploitation within 30 days (98th percentile); no public PoC is known.

What to do: Apply Trend Micro's updates per vendor instructions, as required by CISA's KEV listing, and verify the patched build against Trend Micro's advisory since specific version numbers are not provided here (note that OfficeScan was succeeded by Trend Micro Apex One, so confirm patched status on migrated installs). Inventory for internet-exposed OfficeScan/Apex One management consoles and restrict access to trusted networks, and hunt for evidence of exploitation given the confirmed in-the-wild status.

Affected
Trend Micro OfficeScan
Estimated exposure
large≈10k–100k on-premises OfficeScan management server deployments (estimate; millions of managed endpoints) — OfficeScan is a legacy on-premises endpoint management platform with a large enterprise and SMB installed base that Trend Micro has historically marketed as protecting millions of endpoints, but the vulnerable component is the management…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extract files from an arbitrary zip file to a specific folder on the OfficeScan server, which could potentially lead to remote code execution (RCE). The remote process execution is bound to a web service account, which depending on the web platform used may have restricted permissions. An attempted attack requires user authentication.

CISA Known Exploited Vulnerability
Affected
Trend Micro OfficeScan
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
trendmicro
Products
officescan
Weakness
CWE-22
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news