ZeroHour
Help Net Securitypublished ()ingested @zeljkazorz

Trend Micro fixes two actively exploited zero-days in enterprise products

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2019-18187
Directory Traversal RCE in Trend Micro OfficeScan

Trend Micro OfficeScan contains a directory traversal flaw (CWE-22) in its handling of ZIP archives: when a zip file is extracted to a designated folder on the OfficeScan server, archive entries can escape that folder, allowing an attacker to place files at exploitable locations and achieve remote code execution. The flaw is triggered by getting the server to extract an attacker-influenced ZIP archive into the specific folder on the OfficeScan server. Successful exploitation yields arbitrary code execution on the OfficeScan management server, which typically holds broad control over the managed endpoint fleet and can serve as a foothold for lateral movement. Any organization running an on-premises Trend Micro OfficeScan deployment is affected; the source data does not specify affected version ranges. The vulnerability was added to the CISA KEV catalog on 2021-11-03 (indicating observed exploitation, with ransomware use unknown), and EPSS assigns a 25.1% probability of exploitation within 30 days (98th percentile); no public PoC is known.

Do: Apply Trend Micro's updates per vendor instructions, as required by CISA's KEV listing, and verify the patched build against Trend Micro's advisory since specific version numbers are not provided here (note that OfficeScan was succeeded by Trend Micro Apex One, so confirm patched status on migrated installs). Inventory for internet-exposed OfficeScan/Apex One management consoles and restrict access to trusted networks, and hunt for evidence of exploitation given the confirmed in-the-wild status.

7.525% KEV
  • Trend Micro OfficeScan
large≈10k–100k on-premises OfficeScan management server deployments (estimate; millions of managed endpoints)
CVE-2020-8599
+1 in the same advisory: …8467
Unauthenticated File Write & Auth Bypass in Trend Micro Apex One/OfficeScan

Trend Micro Apex One (2019) and OfficeScan XG on-premises servers ship a vulnerable EXE file that an unauthenticated remote attacker can abuse to write arbitrary data to an arbitrary path on the server and to bypass ROOT login. Because the flaw is reachable over the network and requires no credentials or user interaction, any exposed management server is directly attackable. Successful exploitation effectively grants an attacker full control of the endpoint-management server, which typically holds central administration over an organization's entire endpoint-security estate. Organizations running on-premises Apex One (2019) or OfficeScan XG servers are affected, particularly those whose consoles are reachable from the internet. The vulnerability is confirmed in the wild — it was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 — and its EPSS score of ~11.9% (96th percentile) indicates a meaningful probability of continued exploitation; no public PoC is known.

Do: Apply Trend Micro's updates for Apex One (2019) and OfficeScan XG per the vendor advisory, as this is CISA's required action for KEV-listed vulnerabilities. Identify any internet-exposed Apex One or OfficeScan consoles — especially on-premises management servers reachable on default web/console ports — and restrict or firewall access until patched. After patching, check the server for unexpected file modifications and review accounts/logs for signs of a ROOT login bypass.

9.8
group max
12% KEV
  • Trend Micro Apex One Apex One (2019) on-premises server
  • Trend Micro OfficeScan OfficeScan XG server
largeon the order of 10,000–100,000 deployed Apex One/OfficeScan management servers (tens of thousands of organizations; millions of endpoints behind them)
CVE-2020-8468
Authenticated content validation escape in Trend Micro Apex One, OfficeScan, WFWBS agents

CVE-2020-8468 is a content validation escape (CWE-74, an injection-class flaw) in the client agents of Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security 9.0/9.5/10.0. The attack is network-based but requires the attacker to already hold valid user credentials (CVSS PR:L); once authenticated, they can send crafted content that escapes validation and manipulates certain agent client components on the endpoint. Because the manipulable components are the endpoint security agent itself, impact is rated high for confidentiality, integrity and availability (CVSS 3.1 score 8.8), giving an authenticated attacker a way to tamper with or abuse the protection software on the host. Any organization running these on-premises Trend Micro endpoint agents is affected. The flaw is on CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03) with active exploitation reported in the wild (contemporaneous coverage described attackers attempting to exploit two Apex One zero-days), though a ransomware link is unknown, no public PoC is catalogued, and EPSS estimates a 5.8% probability of exploitation in the next 30 days (93rd percentile).

Do: Apply the Trend Micro-supplied fixes to all Apex One (2019), OfficeScan XG and Worry-Free Business Security 9.0/9.5/10.0 agents per the vendor advisory, as required by the CISA KEV listing. Because exploitation requires valid credentials, review authentication logs for compromised accounts and hunt for signs of unauthorized manipulation of agent components on any unpatched endpoints. Treat unpatched agents as exposed to active attacks; the possible use in ransomware campaigns is currently unknown.

8.86% KEV
  • Trend Micro Apex One 2019 (agent)
  • Trend Micro OfficeScan XG (agent)
  • Trend Micro Worry-Free Business Security 9.0, 9.5, 10.0 (agent)
masslikely on the order of millions of endpoints worldwide (est.)
CVE-2020-8598
+1 in the same advisory: …8470
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow a re

Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow a remote attacker to execute arbitrary code on affected installations with SYSTEM level privileges. Authentication is not required to exploit this vulnerability.

NVD description · AI analysis pending
9.8
group max
13%
  • trendmicro apex one
  • trendmicro officescan
  • trendmicro worry-free business security
Full article251 words · extracted from helpnetsecurity.com · click to collapse

Trend Micro has fixed two actively exploited zero-day vulnerabilities in its Apex One and OfficeScan XG enterprise security products, and advises customers to update to the latest software versions as soon as possible.

Trend Micro zero-days enterprise

About the vulnerabilities

The two zero-days are:

  • CVE-2020-8467, a critical flaw in the migration tool component of the two solutions that could allow remote attackers to execute arbitrary code on affected installations
  • CVE-2020-8468, a high-risk content validation escape vulnerability affecting Apex One and OfficeScan agents, which could allow remote attackers to manipulate certain agent client components.

In both cases, attackers must authenticate to the target endpoint with valid, compromised credentials before attempting exploitation, which means that these flaws are likely to have been exploited by attackers who have already found their way into the enterprise network.

Vulnerable versions

Affected versions Apex One 2019 (on premise) for Windows and OfficeScan XG SP1 and XG for Windows. Fixes have been implemented in:

  • Apex One (on premise) CP 2117
  • OfficeScan XG SP1 CP 5474
  • OfficeScan XG CP 1988

Additional vulnerabilities

In addition to these two zero-days, three additional critical security holes (CVE-2020-8470, CVE-2020-8598 and CVE-2020-8599) have been plugged in these updates. These allow remote attacks without authentication, but Trend Micro has not observed any attempted exploits of those vulnerabilities.

The company did not share the nature of the in-the-wild attacks.

Before this, back in October 2019, Trend Micro fixed CVE-2019-18187, a vulnerability affecting OfficeScan, that has been used by a Chinese hacker group that breached Mitsubishi Electric.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2020/03/18/trend-micro-zero-days-enterprise/