Chinese hackers exploited Trend Micro AV 0day in Mitsubishi Electric hack
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-18187 | Directory Traversal RCE in Trend Micro OfficeScan Trend Micro OfficeScan contains a directory traversal flaw (CWE-22) in its handling of ZIP archives: when a zip file is extracted to a designated folder on the OfficeScan server, archive entries can escape that folder, allowing an attacker to place files at exploitable locations and achieve remote code execution. The flaw is triggered by getting the server to extract an attacker-influenced ZIP archive into the specific folder on the OfficeScan server. Successful exploitation yields arbitrary code execution on the OfficeScan management server, which typically holds broad control over the managed endpoint fleet and can serve as a foothold for lateral movement. Any organization running an on-premises Trend Micro OfficeScan deployment is affected; the source data does not specify affected version ranges. The vulnerability was added to the CISA KEV catalog on 2021-11-03 (indicating observed exploitation, with ransomware use unknown), and EPSS assigns a 25.1% probability of exploitation within 30 days (98th percentile); no public PoC is known. Do: Apply Trend Micro's updates per vendor instructions, as required by CISA's KEV listing, and verify the patched build against Trend Micro's advisory since specific version numbers are not provided here (note that OfficeScan was succeeded by Trend Micro Apex One, so confirm patched status on migrated installs). Inventory for internet-exposed OfficeScan/Apex One management consoles and restrict access to trusted networks, and hunt for evidence of exploitation given the confirmed in-the-wild status. | 7.5 | 25% | KEV |
| large≈10k–100k on-premises OfficeScan management server deployments (estimate; millions of managed endpoints) |
Full article688 words · extracted from securityaffairs.com · click to collapse

Chinese hackers have exploited a zero-day vulnerability the Trend Micro OfficeScan antivirus in the recently disclosed hack of Mitsubishi Electric.
According to ZDNet, the hackers involved in the attack against the Mitsubishi Electric have exploited a zero-day vulnerability in Trend Micro OfficeScan to infect company servers.
This week, Mitsubishi Electric disclosed a security breach that might have exposed personal and confidential corporate data. According to the company, attackers did not obtain sensitive information about defense contracts.
The breach was detected almost eight months ago, on June 28, 2019, with the delay being attributed to the increased complexity of the investigation caused by the attackers deleting activity logs.
“On June 28, last year, a suspicious behavior was detected and investigated on a terminal in our company, and as a result of unauthorized access by a third party, data was transmitted to the outside,” reads a data breach notification published by the company.
The intrusion took place on June 28, 2019, and the company launched an investigation in September 2019. Mitsubishi Electric disclosed the security incident only after two local newspapers, the Asahi Shimbun and Nikkei, reported the security breach.
Mitsubishi Electric had also already notified members of the Japanese government and Ministry of Defense.
The two media outlets attribute the cyber attack to a China-linked cyber espionage group tracked as Tick (aka Bronze Butler).
The hacker group has been targeting Japanese heavy industry, manufacturing and international relations at least since 2012,
According to the experts, the group is linked to the People’s Republic of China and is focused on exfiltrating confidential data.
“According to people involved, Chinese hackers Tick may have been involved. According to Mitsubishi Electric, “logs (to check for leaks) have been deleted and it is not possible to confirm whether or not they actually leaked.” reported the Nikkei.
“According to the company, at least tens of PCs and servers in Japan and overseas have been found to have been compromised. The amount of unauthorized access is approximately 200 megabytes, mainly for documents.”
The security breach was discovered after Mitsubishi Electric staff found a suspicious file on one of the company’s servers, further investigation allowed the company to determine that hack of an employee account.
According to the media, hackers gained access to the networks of around 14 company departments, including sales and the head administrative office. Threat actors stole around 200 MB of files including:
- Personal information and recruitment applicant information (1,987)
- New graduate recruitment applicants who joined the company from October 2017 to April 2020, and experienced recruitment applicants from 2011 to 2016 and our employee information (4,566)
- 2012 Survey results regarding the personnel treatment system implemented for employees in the headquarters in Japan, and information on retired employees of our affiliated companies (1,569)
The attackers have exploited a directory traversal and arbitrary file upload vulnerability, tracked as CVE-2019-18187, in the Trend Micro OfficeScan antivirus.
Trend Micro has now addressed the vulnerability, but we cannot exclude that the hackers have exploited the same issue in attacks against other targets. After the security firm patched the CVE-2019-18187 flaw in October, it warned customers that the issue was being actively exploited by hackers in the wild.
“Trend Micro has released Critical Patches (CP) for Trend Micro OfficeScan 11.0 SP1 and XG which resolve an arbitrary file upload with directory traversal vulnerability.” reads the security advisory published by Trend Micro in October 2019.
“Affected versions of OfficeScan could be exploited by an attacker utilizing a directory traversal vulnerability to extract files from an arbitrary zip file to a specific folder on the OfficeScan server, which could potentially lead to remote code execution (RCE). The remote process execution is bound to a web service account, which depending on the web platform used may have restricted permissions. An attempted attack requires user authentication.”
The issue affects OfficeScan versions XG SP1, XG (Non-SP GM build), 11.0 SP1 for Windows.
“In a case study on its website, Trend Micro lists Mitsubishi Electric as one of the companies that run the OfficeScan suite.” reported ZDNet.
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – Mitsubishi Electric, hacking)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/96805/hacking/trend-micro-av-0day-mitsubishi-electric.html