Trend Micro flaw actively exploited in the wild
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2019-18187 | Directory Traversal RCE in Trend Micro OfficeScan Trend Micro OfficeScan contains a directory traversal flaw (CWE-22) in its handling of ZIP archives: when a zip file is extracted to a designated folder on the OfficeScan server, archive entries can escape that folder, allowing an attacker to place files at exploitable locations and achieve remote code execution. The flaw is triggered by getting the server to extract an attacker-influenced ZIP archive into the specific folder on the OfficeScan server. Successful exploitation yields arbitrary code execution on the OfficeScan management server, which typically holds broad control over the managed endpoint fleet and can serve as a foothold for lateral movement. Any organization running an on-premises Trend Micro OfficeScan deployment is affected; the source data does not specify affected version ranges. The vulnerability was added to the CISA KEV catalog on 2021-11-03 (indicating observed exploitation, with ransomware use unknown), and EPSS assigns a 25.1% probability of exploitation within 30 days (98th percentile); no public PoC is known. Do: Apply Trend Micro's updates per vendor instructions, as required by CISA's KEV listing, and verify the patched build against Trend Micro's advisory since specific version numbers are not provided here (note that OfficeScan was succeeded by Trend Micro Apex One, so confirm patched status on migrated installs). Inventory for internet-exposed OfficeScan/Apex One management consoles and restrict access to trusted networks, and hunt for evidence of exploitation given the confirmed in-the-wild status. | 7.5 | 25% | KEV |
| large≈10k–100k on-premises OfficeScan management server deployments (estimate; millions of managed endpoints) | |
| CVE-2020-24557 | Improper Access Control LPE in Trend Micro Apex One and Worry-Free Business Security Trend Micro Apex One, OfficeScan, and Worry-Free Business Security 10.0 SP1 on Microsoft Windows contain an improper access control flaw that lets an attacker manipulate a specific product folder to temporarily disable the security product and abuse a Windows function to escalate privileges. The attacker must first obtain the ability to execute low-privileged code on the target system; Windows 10 version 1909 (OS Build 18363.719) mitigates the hard-link technique, so earlier Windows versions are the easier targets. Successful exploitation yields local privilege escalation with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8). Any organization running these Trend Micro endpoint agents on unpatched Windows machines is affected, with exposure driven by fleet size rather than internet-facing services. The vulnerability is being exploited in the wild per vendor advisories and news coverage, and CISA added it to the KEV catalog on 2021-11-03 with the required action of applying vendor updates; no public proof-of-concept is documented. Do: Apply Trend Micro's patched builds for Apex One and Worry-Free Business Security 10.0 SP1 per the vendor advisory, as CISA's required action directs. Prioritize hosts running Windows versions older than Windows 10 1909 (OS Build 18363.719), where the hard-link mitigation is absent, and verify no unpatched agents remain in your fleet. Also check endpoints for signs of prior low-privileged code execution and local privilege escalation, since the flaw requires an existing foothold to exploit. | 7.8 | 3% | KEV |
| largehundreds of thousands of managed Windows endpoints (order-of-magnitude estimate) | |
| CVE-2020-8467 | Authenticated RCE in Trend Micro Apex One (2019) and OfficeScan XG Migration Tool CVE-2020-8467 is a remote code execution flaw in the migration tool component of Trend Micro Apex One (2019) and OfficeScan XG, exploitable by remote attackers who already hold valid low-privileged credentials. Because the attack vector is network-based with no user interaction, an authenticated attacker can send crafted input to the migration tool component and execute arbitrary code on the affected installation, with high impact on confidentiality, integrity, and availability. Any organization running the on-premises Apex One (2019) or OfficeScan XG endpoint security platforms is potentially affected. The flaw is being exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2021-11-03, its EPSS score of 10.8% (96th percentile) signals meaningful near-term exploitation risk, and news reports describe attackers actively attempting to exploit it and a companion Apex One zero-day. Do: Apply the latest Trend Micro critical patch for Apex One (2019) and OfficeScan XG per the vendor's security bulletin, as required by the CISA KEV listing. Because exploitation requires valid credentials, audit accounts on the Apex One/OfficeScan management console for compromise or weak passwords, review logs for unexpected requests involving the migration tool component, and restrict console access to trusted networks until patched. | 8.8 | 11% | KEV |
| large≈ hundreds of thousands of enterprise endpoints and management consoles (order of magnitude 10^5) | |
| CVE-2020-8468 | Authenticated content validation escape in Trend Micro Apex One, OfficeScan, WFWBS agents CVE-2020-8468 is a content validation escape (CWE-74, an injection-class flaw) in the client agents of Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security 9.0/9.5/10.0. The attack is network-based but requires the attacker to already hold valid user credentials (CVSS PR:L); once authenticated, they can send crafted content that escapes validation and manipulates certain agent client components on the endpoint. Because the manipulable components are the endpoint security agent itself, impact is rated high for confidentiality, integrity and availability (CVSS 3.1 score 8.8), giving an authenticated attacker a way to tamper with or abuse the protection software on the host. Any organization running these on-premises Trend Micro endpoint agents is affected. The flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with active exploitation reported in the wild (contemporaneous coverage described attackers attempting to exploit two Apex One zero-days), though a ransomware link is unknown, no public PoC is catalogued, and EPSS estimates a 5.8% probability of exploitation in the next 30 days (93rd percentile). Do: Apply the Trend Micro-supplied fixes to all Apex One (2019), OfficeScan XG and Worry-Free Business Security 9.0/9.5/10.0 agents per the vendor advisory, as required by the CISA KEV listing. Because exploitation requires valid credentials, review authentication logs for compromised accounts and hunt for signs of unauthorized manipulation of agent components on any unpatched endpoints. Treat unpatched agents as exposed to active attacks; the possible use in ransomware campaigns is currently unknown. | 8.8 | 6% | KEV |
| masslikely on the order of millions of endpoints worldwide (est.) |
Full article538 words · extracted from securityaffairs.com · click to collapse

Cybersecurity firm Trend Micro revealed that a threat actor is actively exploiting a flaw, tracked as CVE-2020-24557, in its antivirus solutions to gain admin rights on Windows systems.
Security solutions one again are used as attack vectors by threat actors, this time cybersecurity company Trend Micro revealed that attackers are actively exploiting a vulnerability, tracked as CVE-2020-24557, in its antivirus solutions to gain admin rights on Windows systems.
The CVE-2020-24557 vulnerability affects the Apex One and OfficeScan XG enterprise security products. The issue resides in the logic that controls access to the Misc folder, it could be exploited by an attacker to escalate privileges and execute code in the context of SYSTEM.
Experts pointed out that the flaw could be exploited by an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function and achieve privilege escalation.
“A vulnerability in Trend Micro Apex One on Microsoft Windows may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function and attain privilege escalation.” reads the advisory published by Tenable. “An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.”
The flaw was reported to Trend Micro in 2020 by Microsoft researcher Christopher Vella through the Zero-Day Initiative program, and the security firm addressed it in August 2020.
Now the security firm provided an update to its security advisory confirming that the flaw is actively exploited attackers in the wild and urge customers to apply security updates.
“Known vulnerabilities in Apex One, Apex One SaaS and OfficeScan agents could elevate privileges, allow an attacker to manipulate certain product folders to temporarily disable security features, or to temporarily disable certain Windows features. It may be abused.” reads the update published by the
“We have confirmed attacks that exploit known vulnerabilities in the following products.” adds the company. “Each patch that has already been released supports it, so if you have not applied it, please apply it as soon as possible.”
At the time of this writing, Trend Micro did not share details about the attack either the nature of the threat actors that exploited the.
JPCert also published an alert about the above vulnerability, products and versions affected by the issues are:
– Trend Micro Apex One 2019 prior to Build 8422
– Trend Micro Apex One as a Service prior to Build 202008
– OfficeScan prior to XG SP1 Build 5702
“Since the vulnerability is already being exploited in the wild, the users of the affected products are recommended to update the affected system to the latest version as soon as possible. Please refer to the information provided by Trend Micro.” reads the advisory published by JPCert.
In the past, other vulnerabilities in the Apex One and OfficeScan XG security products were disclosed, including CVE-2019-18187, CVE-2020-8467, and CVE-2020-8468, and some of them were exploited by nation-state actors in attacks in the wild.
If you want to receive the weekly Security Affairs Newsletter for free subscribe here.
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, Trend Micro)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/117105/hacking/trend-micro-flaw-cve-2020-24557.html