8.8
CVE-2020-8468
- EPSS 5.75%
- Veröffentlicht 18.03.2020 01:15:12
- Zuletzt bearbeitet 31.10.2025 14:41:42
- Erkennungen
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent client components. An attempted attack requires user authentication.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Apex One Version 2019
Trendmicro ≫ Officescan Version xg Update -
Trendmicro ≫ Officescan Version xg Update sp1
Trendmicro ≫ Worry-free Business Security Version 9.0 Update sp3
Trendmicro ≫ Worry-free Business Security Version 9.5
Trendmicro ≫ Worry-free Business Security Version 10.0 Update -
Trendmicro ≫ Worry-free Business Security Version 10.0 Update sp1
03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog
Trend Micro Multiple Products Content Validation Escape Vulnerability
SchwachstelleTrend Micro Apex One, OfficeScan, and Worry-Free Business Security agents contain a content validation escape vulnerability that could allow an attacker to manipulate certain agent client components.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 5.75% | 0.921 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 6.5 | 8 | 6.4 |
AV:N/AC:L/Au:S/C:P/I:P/A:P
|
| CISA-ADP | 8.8 | 2.8 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
https://success.trendmicro.com/jp/solution/000244253
https://success.trendmicro.com/solution/000245571
https://success.trendmicro.com/jp/solution/000244836
https://success.trendmicro.com/solution/000245572
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8468