VDB

CVE-2020-8467

CVE-2020-8467 PUBLISHED KEV CVSS 6.5 MEDIUM

A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute arbitrary code on affected installations (RCE). An attempted attack requires user authentication.

EPSS 10.90% · 95.6th percentile

Risk Scores

CVSS 2.0
6.5
EPSS Score
10.90%
95.6th percentile

Affected Products

VendorProductVersions
Trend MicroTrend Micro OfficeScan, Trend Micro Apex OneOfficeScan XG (12.0), Apex One 2019 (14.0)
trendmicroapex_one2019
trendmicroofficescanxg, *

Timeline

  • Mar 16, 2020 VulnCheck KEV Exploitation
  • Mar 16, 2020 PoC Published
  • Mar 18, 2020 CVE Published
  • Apr 14, 2021 EPSS Score
  • May 4, 2021 VulnCheck KEV Exploitation
  • Aug 11, 2021 VulnCheck KEV Exploitation
  • Aug 24, 2021 EPSS Score
  • Aug 28, 2021 VulnCheck KEV Exploitation
  • Oct 26, 2021 EPSS Score
  • Nov 3, 2021 CISA KEV Added
  • Nov 3, 2021 VulnCheck KEV Exploitation
  • Nov 8, 2021 PoC Published
Open in Interactive Console →
$ Console Community · 100/wk Open console ›