CVE-2020-8467
KEVlargeAuthenticated RCE in Trend Micro Apex One (2019) and OfficeScan XG Migration Tool
CISA: Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability
CVE-2020-8467 is a remote code execution flaw in the migration tool component of Trend Micro Apex One (2019) and OfficeScan XG, exploitable by remote attackers who already hold valid low-privileged credentials. Because the attack vector is network-based with no user interaction, an authenticated attacker can send crafted input to the migration tool component and execute arbitrary code on the affected installation, with high impact on confidentiality, integrity, and availability. Any organization running the on-premises Apex One (2019) or OfficeScan XG endpoint security platforms is potentially affected. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, its EPSS score of 10.8% (96th percentile) signals meaningful near-term exploitation risk, and news reports describe attackers actively attempting to exploit it and a companion Apex One zero-day.
What to do: Apply the latest Trend Micro critical patch for Apex One (2019) and OfficeScan XG per the vendor's security bulletin, as required by the CISA KEV listing. Because exploitation requires valid credentials, audit accounts on the Apex One/OfficeScan management console for compromise or weak passwords, review logs for unexpected requests involving the migration tool component, and restrict console access to trusted networks until patched.
| Trend Micro Apex One (2019) | — |
| Trend Micro OfficeScan XG | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute arbitrary code on affected installations (RCE). An attempted attack requires user authentication.
- Affected
- Trend Micro Apex One and OfficeScan
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- trendmicro
- Products
- apex one, officescan
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H