9.4

CVE-2020-8470

Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow an attacker to delete any file on the server with SYSTEM level privileges. Authentication is not required to exploit this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Apex One Version 2019
Trendmicro ≫ Officescan Version xg
Trendmicro ≫ Officescan Version xg Update sp1
Trendmicro ≫ Worry-free Business Security Version 9.0 Update sp3
Trendmicro ≫ Worry-free Business Security Version 10.0 Update -
Trendmicro ≫ Worry-free Business Security Version 10.0 Update sp1
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 4.58% 0.907
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.5 3.9 3.6
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N
NIST 9.4 10 9.2
AV:N/AC:L/Au:N/C:N/I:C/A:C
Es wurden noch keine Informationen zu CWE veröffentlicht.
https://success.trendmicro.com/jp/solution/000244253
Patch
Vendor Advisory
https://success.trendmicro.com/solution/000245571
Patch
Vendor Advisory
https://success.trendmicro.com/jp/solution/000244836
Patch
Vendor Advisory
https://success.trendmicro.com/solution/000245572
Patch
Vendor Advisory