VDB
CVE-2020-8468
CVE-2020-8468
PUBLISHED
KEV
CVSS 6.5 MEDIUM
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent client components. An attempted attack requires user authentication.
EPSS 6.17% · 93.1th percentile
Risk Scores
CVSS 2.0
6.5
EPSS Score
6.17%
93.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trend Micro | Trend Micro OfficeScan, Trend Micro Apex One, Trend Micro Worry-Free Business Security (WFBS) | * |
| trendmicro | officescan | xg, xg |
| trendmicro | apex_one | 2019 |
| trendmicro | worry-free_business_security | 10.0, 9.0, 9.5 |
Timeline
- Mar 16, 2020 VulnCheck KEV Exploitation
- Mar 16, 2020 PoC Published
- Mar 18, 2020 CVE Published
- Apr 14, 2021 EPSS Score
- May 4, 2021 VulnCheck KEV Exploitation
- Jun 23, 2021 EPSS Score
- Aug 1, 2021 VulnCheck KEV Exploitation
- Aug 11, 2021 VulnCheck KEV Exploitation
- Aug 28, 2021 VulnCheck KEV Exploitation
- Oct 26, 2021 EPSS Score
- Nov 3, 2021 CISA KEV Added
- Nov 3, 2021 VulnCheck KEV Exploitation
References
- https://success.trendmicro.com/solution/000245571 url
- https://success.trendmicro.com/jp/solution/000244253 url
- https://success.trendmicro.com/solution/000245572 url
- https://success.trendmicro.com/jp/solution/000244836 url
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8468 url
- https://nvd.nist.gov/vuln/detail/CVE-2020-8468 advisory