Back
CVE-2020-8599
CRITICAL
CISA KEV
Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected installations and bypass ROOT login. Authentication is not required to exploit this vulnerability.
Published: Mar 18, 2020
Modified: Jun 17, 2026
NVD-CWE-noinfo
CVSS Metrics
CVSSv3
Attack Vector:
NETWORK
Attack Complexity:
LOW
Privileges Required:
NONE
User Interaction:
NONE
Scope:
UNCHANGED
Confidentiality Impact:
HIGH
Integrity Impact:
HIGH
Availability Impact:
HIGH
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected Products (3)
| Vendor | Product | Version |
|---|---|---|
| trendmicro | apex_one | 2019 |
| trendmicro | officescan | xg |
| trendmicro | officescan | xg |
GitHub Security Advisory GHSA-r3h3-2xcv-m95h
Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could...
References (5)
- https://success.trendmicro.com/jp/solution/000244253 Broken Link, Patch, Vendor Advisory
- https://success.trendmicro.com/solution/000245571 Broken Link, Patch, Vendor Advisory
- https://success.trendmicro.com/jp/solution/000244253 Broken Link, Patch, Vendor Advisory
- https://success.trendmicro.com/solution/000245571 Broken Link, Patch, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8599 US Government Resource
Risk Scores
CVSS Score
9.8 / 10
EPSS Score
11.86%
Top 4% most likely to be exploited
Threat Score
72.8 / 100
CISA Known Exploited
Date Added:
2021-11-03
Due Date:
2022-05-03
Required Action:
Apply updates per vendor instructions.
Data Sources
NVD
CISA KEV
EPSS
GitHub