10
CVE-2020-8598
- EPSS 8.46%
- Veröffentlicht 18.03.2020 01:15:12
- Zuletzt bearbeitet 21.11.2024 05:39:06
- Quelle security@trendmicro.com
- CVE-Watchlists
- Unerledigt
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow a remote attacker to execute arbitrary code on affected installations with SYSTEM level privileges. Authentication is not required to exploit this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Apex One Version2019
Trendmicro ≫ Officescan Versionxg
Trendmicro ≫ Officescan Versionxg Updatesp1
Trendmicro ≫ Worry-free Business Security Version9.0 Updatesp3
Trendmicro ≫ Worry-free Business Security Version9.5
Trendmicro ≫ Worry-free Business Security Version10.0 Update-
Trendmicro ≫ Worry-free Business Security Version10.0 Updatesp1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 8.46% | 0.92 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| nvd@nist.gov | 10 | 10 | 10 |
AV:N/AC:L/Au:N/C:C/I:C/A:C
|
CWE-306 Missing Authentication for Critical Function
The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.