CVE-2019-18187 is a critical directory traversal vulnerability affecting Trend Micro OfficeScan versions 11.0 and XG (12.0) on Microsoft Windows. An authenticated attacker can exploit this flaw to extract arbitrary files from a malicious zip archive to a specific server directory, potentially leading to remote code execution. This vulnerability carries a CVSS score of 7.5 (HIGH) and an EPSS score indicating a very high likelihood of exploitation, with a FAUCET Risk Score of 100/100. It is actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog and media reports linking it to breaches at Mitsubishi Electric and other Japanese defense contractors. Despite active exploitation, no public exploit code (Metasploit, Nuclei, ExploitDB) is currently available, though it has garnered significant community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
11.0CPE matchmatch criteria | cpe:2.3:a:trendmicro:officescan:11.0:sp1:*:*:*:*:*:* | ||
xgCPE matchmatch criteria | cpe:2.3:a:trendmicro:officescan:xg:*:*:*:*:*:*:* | ||
xgCPE matchmatch criteria | cpe:2.3:a:trendmicro:officescan:xg:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.