CVE Vulnerabilities

CVE-2020-8599

Published: Mar 18, 2020 | Modified: Jul 12, 2022
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
10 HIGH
AV:N/AC:L/Au:N/C:C/I:C/A:C
RedHat/V2
RedHat/V3
Ubuntu

Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected installations and bypass ROOT login. Authentication is not required to exploit this vulnerability.

Affected Software

Name Vendor Start Version End Version
Apex_one Trendmicro 2019 (including) 2019 (including)
Officescan Trendmicro xg (including) xg (including)
Officescan Trendmicro xg-sp1 (including) xg-sp1 (including)

References