Trend Micro addresses two issues exploited by hackers in the wild
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-8467 | Authenticated RCE in Trend Micro Apex One (2019) and OfficeScan XG Migration Tool CVE-2020-8467 is a remote code execution flaw in the migration tool component of Trend Micro Apex One (2019) and OfficeScan XG, exploitable by remote attackers who already hold valid low-privileged credentials. Because the attack vector is network-based with no user interaction, an authenticated attacker can send crafted input to the migration tool component and execute arbitrary code on the affected installation, with high impact on confidentiality, integrity, and availability. Any organization running the on-premises Apex One (2019) or OfficeScan XG endpoint security platforms is potentially affected. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, its EPSS score of 10.8% (96th percentile) signals meaningful near-term exploitation risk, and news reports describe attackers actively attempting to exploit it and a companion Apex One zero-day. Do: Apply the latest Trend Micro critical patch for Apex One (2019) and OfficeScan XG per the vendor's security bulletin, as required by the CISA KEV listing. Because exploitation requires valid credentials, audit accounts on the Apex One/OfficeScan management console for compromise or weak passwords, review logs for unexpected requests involving the migration tool component, and restrict console access to trusted networks until patched. | 8.8 | 11% | KEV |
| large≈ hundreds of thousands of enterprise endpoints and management consoles (order of magnitude 10^5) | |
| CVE-2020-8468 | Authenticated content validation escape in Trend Micro Apex One, OfficeScan, WFWBS agents CVE-2020-8468 is a content validation escape (CWE-74, an injection-class flaw) in the client agents of Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security 9.0/9.5/10.0. The attack is network-based but requires the attacker to already hold valid user credentials (CVSS PR:L); once authenticated, they can send crafted content that escapes validation and manipulates certain agent client components on the endpoint. Because the manipulable components are the endpoint security agent itself, impact is rated high for confidentiality, integrity and availability (CVSS 3.1 score 8.8), giving an authenticated attacker a way to tamper with or abuse the protection software on the host. Any organization running these on-premises Trend Micro endpoint agents is affected. The flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with active exploitation reported in the wild (contemporaneous coverage described attackers attempting to exploit two Apex One zero-days), though a ransomware link is unknown, no public PoC is catalogued, and EPSS estimates a 5.8% probability of exploitation in the next 30 days (93rd percentile). Do: Apply the Trend Micro-supplied fixes to all Apex One (2019), OfficeScan XG and Worry-Free Business Security 9.0/9.5/10.0 agents per the vendor advisory, as required by the CISA KEV listing. Because exploitation requires valid credentials, review authentication logs for compromised accounts and hunt for signs of unauthorized manipulation of agent components on any unpatched endpoints. Treat unpatched agents as exposed to active attacks; the possible use in ransomware campaigns is currently unknown. | 8.8 | 6% | KEV |
| masslikely on the order of millions of endpoints worldwide (est.) |
Full article314 words · extracted from securityaffairs.com · click to collapse

Trend Micro has addressed several serious vulnerabilities in its products, including two flaws that have been exploited in the wild.
Trend Micro has released security updates to address several serious flaws in its Worry-Free Business Security, Apex One and OfficeScan products, including a couple of vulnerabilities that have been exploited by threat actors in the wild.
Both vulnerabilities exploited in the wild were found by the researchers of the company, but the company did not release details about the attacks.
The first issue, tracked as CVE-2020-8467, impacts the migration tool component of Apex One and OfficeScan. It could be exploited by a remote, authenticated attacker to execute arbitrary code on vulnerable installs.
“A migration tool component of Trend Micro Apex One and OfficeScan contains a vulnerability which could allow remote attackers to execute arbitrary code on affected installations (RCE). An attempted attack requires user authentication.” reads the advisory published by Trend Micro.
The vulnerability rated as critical severity has received a CVSS score of 9.1.
The second vulnerability exploited in the wild, tracked as CVE-2020-8468 is a content validation escape issue that affects the agents for Worry-Free Business Security, Apex One and OfficeScan. The vulnerability could be exploited by an authenticated attacker to “manipulate certain agent client components.”
“Trend Micro Worry-Free Business Security agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent client components. An attempted attack requires user authentication.” reads the advisory.
The CVE-2020-8468 vulnerability, rated as High severity has a CVSS score of 8.0.
Experts pointed out that both issues have to be chained with other vulnerabilities to be exploited in attacks in the wild.
In January, Chinese hackers have exploited another zero-day vulnerability in the Trend Micro OfficeScan antivirus in an attack that hit Mitsubishi Electric.
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, cybercrime)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/99893/hacking/trend-micro-flaws.html