ZeroHour

CVE-2020-8467

KEVlarge

Authenticated RCE in Trend Micro Apex One (2019) and OfficeScan XG Migration Tool

CISA: Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability

CVSS 3.1
8.8 high
EPSS
11%p96
Published
()
KEV added
AI analysis

CVE-2020-8467 is a remote code execution flaw in the migration tool component of Trend Micro Apex One (2019) and OfficeScan XG, exploitable by remote attackers who already hold valid low-privileged credentials. Because the attack vector is network-based with no user interaction, an authenticated attacker can send crafted input to the migration tool component and execute arbitrary code on the affected installation, with high impact on confidentiality, integrity, and availability. Any organization running the on-premises Apex One (2019) or OfficeScan XG endpoint security platforms is potentially affected. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, its EPSS score of 10.8% (96th percentile) signals meaningful near-term exploitation risk, and news reports describe attackers actively attempting to exploit it and a companion Apex One zero-day.

What to do: Apply the latest Trend Micro critical patch for Apex One (2019) and OfficeScan XG per the vendor's security bulletin, as required by the CISA KEV listing. Because exploitation requires valid credentials, audit accounts on the Apex One/OfficeScan management console for compromise or weak passwords, review logs for unexpected requests involving the migration tool component, and restrict console access to trusted networks until patched.

Affected
Trend Micro Apex One (2019)
Trend Micro OfficeScan XG
Estimated exposure
large≈ hundreds of thousands of enterprise endpoints and management consoles (order of magnitude 10^5) — Estimated from the fact that Apex One/OfficeScan has been Trend Micro's widely deployed on-premises enterprise endpoint security platform, where typical enterprise agent fleets and internet-reachable management consoles plausibly put the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute arbitrary code on affected installations (RCE). An attempted attack requires user authentication.

CISA Known Exploited Vulnerability
Affected
Trend Micro Apex One and OfficeScan
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
trendmicro
Products
apex one, officescan
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news