ZeroHour

CVE-2020-8468

KEVmass

Authenticated content validation escape in Trend Micro Apex One, OfficeScan, WFWBS agents

CISA: Trend Micro Multiple Products Content Validation Escape Vulnerability

CVSS 3.1
8.8 high
EPSS
6%p93
Published
()
KEV added
AI analysis

CVE-2020-8468 is a content validation escape (CWE-74, an injection-class flaw) in the client agents of Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security 9.0/9.5/10.0. The attack is network-based but requires the attacker to already hold valid user credentials (CVSS PR:L); once authenticated, they can send crafted content that escapes validation and manipulates certain agent client components on the endpoint. Because the manipulable components are the endpoint security agent itself, impact is rated high for confidentiality, integrity and availability (CVSS 3.1 score 8.8), giving an authenticated attacker a way to tamper with or abuse the protection software on the host. Any organization running these on-premises Trend Micro endpoint agents is affected. The flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with active exploitation reported in the wild (contemporaneous coverage described attackers attempting to exploit two Apex One zero-days), though a ransomware link is unknown, no public PoC is catalogued, and EPSS estimates a 5.8% probability of exploitation in the next 30 days (93rd percentile).

What to do: Apply the Trend Micro-supplied fixes to all Apex One (2019), OfficeScan XG and Worry-Free Business Security 9.0/9.5/10.0 agents per the vendor advisory, as required by the CISA KEV listing. Because exploitation requires valid credentials, review authentication logs for compromised accounts and hunt for signs of unauthorized manipulation of agent components on any unpatched endpoints. Treat unpatched agents as exposed to active attacks; the possible use in ransomware campaigns is currently unknown.

Affected
Trend Micro Apex One2019 (agent)
Trend Micro OfficeScanXG (agent)
Trend Micro Worry-Free Business Security9.0, 9.5, 10.0 (agent)
Estimated exposure
masslikely on the order of millions of endpoints worldwide (est.) — Trend Micro's OfficeScan/Apex One/Worry-Free line has historically been among the most widely deployed enterprise endpoint-protection families with a cumulative installed base in the millions, though the affected builds are on-premises…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent client components. An attempted attack requires user authentication.

CISA Known Exploited Vulnerability
Affected
Trend Micro Apex One, OfficeScan and Worry-Free Business Security Agents
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
trendmicro
Products
apex one, officescan, worry-free business security
Weakness
CWE-74
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news