8.8

CVE-2020-8468

Warnung
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent client components. An attempted attack requires user authentication.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Apex One Version 2019
Trendmicro ≫ Officescan Version xg Update -
Trendmicro ≫ Officescan Version xg Update sp1
Trendmicro ≫ Worry-free Business Security Version 9.0 Update sp3
Trendmicro ≫ Worry-free Business Security Version 10.0 Update -
Trendmicro ≫ Worry-free Business Security Version 10.0 Update sp1

03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog

Trend Micro Multiple Products Content Validation Escape Vulnerability

Schwachstelle

Trend Micro Apex One, OfficeScan, and Worry-Free Business Security agents contain a content validation escape vulnerability that could allow an attacker to manipulate certain agent client components.

Beschreibung

Apply updates per vendor instructions.

Erforderliche Maßnahmen
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 5.75% 0.921
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
NIST 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CISA-ADP 8.8 2.8 5.9
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

https://success.trendmicro.com/jp/solution/000244253
Patch
Vendor Advisory
https://success.trendmicro.com/solution/000245571
Patch
Vendor Advisory
https://success.trendmicro.com/jp/solution/000244836
Patch
Vendor Advisory
https://success.trendmicro.com/solution/000245572
Patch
Vendor Advisory
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8468
US Government Resource