CVE-2020-8468
Trend Micro Multiple Products Content Validation Escape Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
YesDecision
Descriptions
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent client components. An attempted attack requires user authentication.
Los agentes de Trend Micro Apex One (2019), OfficeScan XG y Worry-Free Business Security versiones (9.0, 9.5, 10.0), están afectados por una vulnerabilidad de escape de comprobación de contenido que podría permitir a un atacante manipular determinados componentes del cliente del agente. Un intento de ataque requiere autenticación de usuario.
Trend Micro Apex One, OfficeScan, and Worry-Free Business Security agents contain a content validation escape vulnerability that could allow an attacker to manipulate certain agent client components.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2020-01-30 CVE Reserved
- 2020-03-18 CVE Published
- 2021-11-03 Exploited in Wild
- 2022-05-03 KEV Due Date
- 2023-03-07 EPSS Updated
- 2024-08-04 CVE Updated
- ---------- First Exploit
CWE
- CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
CAPEC
References (4)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://success.trendmicro.com/jp/solution/000244253 | 2022-07-12 | |
https://success.trendmicro.com/jp/solution/000244836 | 2022-07-12 | |
https://success.trendmicro.com/solution/000245571 | 2022-07-12 | |
https://success.trendmicro.com/solution/000245572 | 2022-07-12 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Trendmicro Search vendor "Trendmicro" | Apex One Search vendor "Trendmicro" for product "Apex One" | 2019 Search vendor "Trendmicro" for product "Apex One" and version "2019" | - |
Affected
| ||||||
Trendmicro Search vendor "Trendmicro" | Officescan Search vendor "Trendmicro" for product "Officescan" | xg Search vendor "Trendmicro" for product "Officescan" and version "xg" | - |
Affected
| ||||||
Trendmicro Search vendor "Trendmicro" | Officescan Search vendor "Trendmicro" for product "Officescan" | xg Search vendor "Trendmicro" for product "Officescan" and version "xg" | sp1 |
Affected
| ||||||
Trendmicro Search vendor "Trendmicro" | Worry-free Business Security Search vendor "Trendmicro" for product "Worry-free Business Security" | 9.0 Search vendor "Trendmicro" for product "Worry-free Business Security" and version "9.0" | sp3 |
Affected
| ||||||
Trendmicro Search vendor "Trendmicro" | Worry-free Business Security Search vendor "Trendmicro" for product "Worry-free Business Security" | 9.5 Search vendor "Trendmicro" for product "Worry-free Business Security" and version "9.5" | - |
Affected
| ||||||
Trendmicro Search vendor "Trendmicro" | Worry-free Business Security Search vendor "Trendmicro" for product "Worry-free Business Security" | 10.0 Search vendor "Trendmicro" for product "Worry-free Business Security" and version "10.0" | - |
Affected
| ||||||
Trendmicro Search vendor "Trendmicro" | Worry-free Business Security Search vendor "Trendmicro" for product "Worry-free Business Security" | 10.0 Search vendor "Trendmicro" for product "Worry-free Business Security" and version "10.0" | sp1 |
Affected
|