CVE-2020-8468

Severity CVSS v4.0:
Pending analysis
Type:
CWE-74 Injection
Publication date:
18/03/2020
Last modified:
31/10/2025

Description

Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent client components. An attempted attack requires user authentication.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:officescan:xg:-:*:*:*:*:*:*
cpe:2.3:a:trendmicro:officescan:xg:sp1:*:*:*:*:*:*
cpe:2.3:a:trendmicro:worry-free_business_security:9.0:sp3:*:*:*:*:*:*
cpe:2.3:a:trendmicro:worry-free_business_security:9.5:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:worry-free_business_security:10.0:-:*:*:*:*:*:*
cpe:2.3:a:trendmicro:worry-free_business_security:10.0:sp1:*:*:*:*:*:*