CVE-2020-8467 is a critical remote code execution (RCE) vulnerability affecting Trend Micro Apex One (2019) and OfficeScan XG, specifically within a migration tool component. This flaw allows authenticated remote attackers to execute arbitrary code on vulnerable installations. With a CVSS score of 8.8 (High), the vulnerability has a low attack complexity and high impact on confidentiality, integrity, and availability. Notably, this CVE is actively exploited in the wild, as confirmed by its presence in the KEV catalog, and has garnered significant community discussion and media coverage despite a lack of public exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2019CPE matchmatch criteria | cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:*:*:*:* | ||
xgCPE matchmatch criteria | cpe:2.3:a:trendmicro:officescan:xg:-:*:*:*:*:*:* | ||
xgCPE matchmatch criteria | cpe:2.3:a:trendmicro:officescan:xg:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.