CVE Vulnerabilities

CVE-2020-8470

Published: Mar 18, 2020 | Modified: Jul 21, 2021
CVSS 3.x
7.5
HIGH
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
CVSS 2.x
9.4 HIGH
AV:N/AC:L/Au:N/C:N/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow an attacker to delete any file on the server with SYSTEM level privileges. Authentication is not required to exploit this vulnerability.

Affected Software

Name Vendor Start Version End Version
Apex_one Trendmicro 2019 (including) 2019 (including)
Officescan Trendmicro xg (including) xg (including)
Officescan Trendmicro xg-sp1 (including) xg-sp1 (including)
Worry-free_business_security Trendmicro 9.0-sp3 (including) 9.0-sp3 (including)
Worry-free_business_security Trendmicro 9.5 (including) 9.5 (including)
Worry-free_business_security Trendmicro 10.0 (including) 10.0 (including)
Worry-free_business_security Trendmicro 10.0-sp1 (including) 10.0-sp1 (including)

References