CVE-2020-8599
Last modified
CVE-2020-8599 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected installations and bypass ROOT login. Authentication is not required to exploit this vulnerability.. CISA has confirmed active exploitation in the wild. EPSS estimates a 11.58% chance of exploitation in the next 30 days.
Description
Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected installations and bypass ROOT login. Authentication is not required to exploit this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Exploitation Status
This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Trendmicro | Apex One | 2019 |
| Trendmicro | Officescan | xg |
References
- https://success.trendmicro.com/jp/solution/000244253Broken Link, Patch, Vendor Advisory
- https://success.trendmicro.com/solution/000245571Broken Link, Patch, Vendor Advisory
- https://success.trendmicro.com/jp/solution/000244253Broken Link, Patch, Vendor Advisory
- https://success.trendmicro.com/solution/000245571Broken Link, Patch, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8599US Government Resource
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2020-8599?
How severe is CVE-2020-8599?
How do I fix CVE-2020-8599?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-8592eG Manager 7.1.2 allows SQL Injection via the user parameter…9.8
- CVE-2020-8594The Ninja Forms plugin 3.4.22 for WordPress has Multiple Sto…5.4
- CVE-2020-8595Istio versions 1.2.10 (End of Life) and prior, 1.3 through 1…7.3
- CVE-2020-8596participants-database.php in the Participants Database plugi…7.5
- CVE-2020-8597eap.c in pppd in ppp 2.4.2 through 2.4.8 has an rhostname bu…9.8
- CVE-2020-8598Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Bu…9.8
- CVE-2020-8600Trend Micro Worry-Free Business Security (9.0, 9.5, 10.0) is…9.8
- CVE-2020-8601Trend Micro Vulnerability Protection 2.0 is affected by a vu…7.8
- CVE-2020-8602A vulnerability in the management consoles of Trend Micro De…7.2
- CVE-2020-8603A cross-site scripting vulnerability (XSS) in Trend Micro In…6.1
- CVE-2020-8604A vulnerability in Trend Micro InterScan Web Security Virtua…7.5
- CVE-2020-8605A vulnerability in Trend Micro InterScan Web Security Virtua…8.8
Are you affected by CVE-2020-8599?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
