CVE-2020-8470
- EPSS 1.12%
- Veröffentlicht 18.03.2020 01:15:12
- Zuletzt bearbeitet 21.11.2024 05:38:54
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow an attacker to delete any file on the server with SYSTEM level privileges. Authentication is n...
- EPSS 8.46%
- Veröffentlicht 18.03.2020 01:15:12
- Zuletzt bearbeitet 21.11.2024 05:39:06
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow a remote attacker to execute arbitrary code on affected installations with SYSTEM level privil...
- EPSS 57.86%
- Veröffentlicht 18.03.2020 01:15:12
- Zuletzt bearbeitet 31.10.2025 14:41:21
Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected installations and bypass ROOT login. Authentication is not required to expl...
CVE-2020-8467
- EPSS 27.58%
- Veröffentlicht 18.03.2020 01:15:11
- Zuletzt bearbeitet 31.10.2025 14:42:14
A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute arbitrary code on affected installations (RCE). An attempted attack requires user authentication.
CVE-2019-19692
- EPSS 0.56%
- Veröffentlicht 20.12.2019 16:15:12
- Zuletzt bearbeitet 21.11.2024 04:35:12
Trend Micro Apex One (2019) is affected by a cross-site scripting (XSS) vulnerability on the product console. Note that the Japanese version of the product is NOT affected.
CVE-2019-19691
- EPSS 0.53%
- Veröffentlicht 20.12.2019 16:15:11
- Zuletzt bearbeitet 21.11.2024 04:35:12
A vulnerability in Trend Micro Apex One and OfficeScan XG could allow an attacker to expose a masked credential key by manipulating page elements using development tools. Note that the attacker must already have admin/root privileges on the product c...
CVE-2019-18188
- EPSS 2.68%
- Veröffentlicht 28.10.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:32:47
Trend Micro Apex One could be exploited by an attacker utilizing a command injection vulnerability to extract files from an arbitrary zip file to a specific folder on the Apex One server, which could potentially lead to remote code execution (RCE). T...
- EPSS 0.6%
- Veröffentlicht 28.10.2019 20:15:11
- Zuletzt bearbeitet 21.11.2024 04:32:47
A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker to bypass authentication and log on to an affected product's management console as a root user. The ...
CVE-2019-9489
- EPSS 0.57%
- Veröffentlicht 05.04.2019 23:29:00
- Zuletzt bearbeitet 21.11.2024 04:51:43
A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (versions XG and 11.0), and Worry-Free Business Security (versions 10.0, 9.5 and 9.0) could allow an attacker to modify arbitrary files on the affected product's management conso...