ZeroHour

CVE-2020-8599

KEVlarge

Unauthenticated File Write & Auth Bypass in Trend Micro Apex One/OfficeScan

CISA: Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability

CVSS 3.1
9.8 critical
EPSS
12%p96
Published
()
KEV added
AI analysis

Trend Micro Apex One (2019) and OfficeScan XG on-premises servers ship a vulnerable EXE file that an unauthenticated remote attacker can abuse to write arbitrary data to an arbitrary path on the server and to bypass ROOT login. Because the flaw is reachable over the network and requires no credentials or user interaction, any exposed management server is directly attackable. Successful exploitation effectively grants an attacker full control of the endpoint-management server, which typically holds central administration over an organization's entire endpoint-security estate. Organizations running on-premises Apex One (2019) or OfficeScan XG servers are affected, particularly those whose consoles are reachable from the internet. The vulnerability is confirmed in the wild — it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 — and its EPSS score of ~11.9% (96th percentile) indicates a meaningful probability of continued exploitation; no public PoC is known.

What to do: Apply Trend Micro's updates for Apex One (2019) and OfficeScan XG per the vendor advisory, as this is CISA's required action for KEV-listed vulnerabilities. Identify any internet-exposed Apex One or OfficeScan consoles — especially on-premises management servers reachable on default web/console ports — and restrict or firewall access until patched. After patching, check the server for unexpected file modifications and review accounts/logs for signs of a ROOT login bypass.

Affected
Trend Micro Apex OneApex One (2019) on-premises server
Trend Micro OfficeScanOfficeScan XG server
Estimated exposure
largeon the order of 10,000–100,000 deployed Apex One/OfficeScan management servers (tens of thousands of organizations; millions of endpoints behind them) — Apex One and OfficeScan are widely deployed on-premises enterprise endpoint-security management servers at small businesses through large enterprises, and historical public scans show thousands to tens of thousands of exposed consoles, so…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected installations and bypass ROOT login. Authentication is not required to exploit this vulnerability.

CISA Known Exploited Vulnerability
Affected
Trend Micro Apex One and OfficeScan
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
trendmicro
Products
apex one, officescan
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news