VDB
CVE-2020-8467
CVE-2020-8467
PUBLISHED
KEV
CVSS 6.5 MEDIUM
A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute arbitrary code on affected installations (RCE). An attempted attack requires user authentication.
EPSS 10.90% · 95.6th percentile
Risk Scores
CVSS 2.0
6.5
EPSS Score
10.90%
95.6th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trend Micro | Trend Micro OfficeScan, Trend Micro Apex One | OfficeScan XG (12.0), Apex One 2019 (14.0) |
| trendmicro | apex_one | 2019 |
| trendmicro | officescan | xg, * |
Timeline
- Mar 16, 2020 VulnCheck KEV Exploitation
- Mar 16, 2020 PoC Published
- Mar 18, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- May 4, 2021 VulnCheck KEV Exploitation
- Aug 11, 2021 VulnCheck KEV Exploitation
- Aug 24, 2021 EPSS Score
- Aug 28, 2021 VulnCheck KEV Exploitation
- Oct 26, 2021 EPSS Score
- Nov 3, 2021 CISA KEV Added
- Nov 3, 2021 VulnCheck KEV Exploitation
- Nov 8, 2021 PoC Published