CVE-2020-8467

HIGH(8.8)KEVElevated Risk

Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability

Description

CVE-2020-8467 is a high-severity remote code execution vulnerability affecting Trend Micro Apex One (2019) and OfficeScan XG. A migration tool component within these products contains an unspecified vulnerability that allows remote attackers to execute arbitrary code on affected installations. Although an attempted attack requires user authentication, the impact is severe with full compromise of confidentiality, integrity, and availability. CISA has confirmed active exploitation by listing this vulnerability in the Known Exploited Vulnerabilities catalog. The EPSS score of 30.16% (96.60th percentile) indicates a significant probability of exploitation activity.

KEV Information

Vendor
Trend Micro
Product
Apex One and OfficeScan
Date Added
November 3, 2021
Due Date
May 3, 2022
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9

Affected Products

VendorProductVersion
trendmicroapex one2019
trendmicroofficescanxg

Multiple CVSS Assessments

Source: [email protected](Primary)
8.8
HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
8.8
HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

No specific CWE has been assigned to CVE-2020-8467 in the NVD database. The vulnerability resides in a migration tool component of Trend Micro Apex One and OfficeScan that allows remote code execution, but the exact underlying weakness type has not been publicly disclosed by the vendor.

Impact Analysis

CVE-2020-8467 carries a CVSS 3.1 score of 8.8 (HIGH), indicating a severe threat to affected environments. The vulnerability is exploitable over the network with low attack complexity, requires only low-level privileges, and needs no user interaction, making it straightforward to exploit once an attacker has authenticated access. Successful exploitation results in full impact across all three security dimensions: Confidentiality (High) exposes sensitive data on the endpoint security management server; Integrity (High) allows modification of security configurations, policies, and system files; and Availability (High) enables disruption of endpoint protection services across the managed environment. The EPSS score of 30.16% places this in the 96.60th percentile, reflecting significant exploitation activity. Since Apex One and OfficeScan are endpoint security management platforms, compromising these systems could disable security protections across an entire organization.

Exploit Maturity

CVE-2020-8467 is confirmed as actively exploited through its listing in the CISA Known Exploited Vulnerabilities catalog, with a remediation deadline of 2022-05-03. The EPSS score of 30.16% (96.60th percentile) indicates significant exploitation activity. No public proof-of-concept exploit code has been identified in the NVD references, suggesting that exploitation may be occurring through privately developed tools or targeted attack campaigns. Trend Micro’s advisory confirms that this vulnerability was exploited in the wild prior to patch availability, making it a former zero-day. The fact that the vulnerability exists in a security product’s migration tool component makes it an attractive target for advanced threat actors seeking to disable endpoint protection.

Remediation

  1. Apply vendor patches immediately as required by CISA KEV. Install the security patches provided by Trend Micro for Apex One 2019 and OfficeScan XG as documented in the vendor advisories at success.trendmicro.com.
  2. Verify that all Trend Micro Apex One 2019 and OfficeScan XG installations across the organization have been updated. Pay particular attention to the migration tool component that contains the vulnerability.
  3. Restrict network access to the Apex One and OfficeScan management consoles and migration tool interfaces using firewall rules, ensuring only authorized administrators can access these services from trusted networks.
  4. Review authentication logs for the Apex One and OfficeScan management interfaces for suspicious login activity, as exploitation requires user authentication. Investigate any unauthorized or anomalous access attempts.
  5. Implement network segmentation to isolate endpoint security management servers from general network traffic, and deploy monitoring to detect unusual process execution or network connections originating from these systems.

Technical Details

CVE-2020-8467 targets a migration tool component within Trend Micro Apex One (2019) and OfficeScan XG that contains an unspecified vulnerability enabling remote code execution. The CVSS vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) reveals that the attack is network-based with low complexity, requires low-level privileges (authenticated access), and does not need user interaction. The scope is unchanged, meaning exploitation impacts the vulnerable component directly rather than cascading to other systems. The exact technical mechanism has not been publicly disclosed by Trend Micro, which classified it as an unspecified vulnerability in the migration tool. The requirement for authentication (PR:L) suggests the attacker needs valid credentials or session access to the management interface, but once authenticated, the path to code execution is straightforward with an exploitability score of 2.8.

Frequently Asked Questions

Is CVE-2020-8467 being actively exploited?

Yes. CVE-2020-8467 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation. Trend Micro has acknowledged that this vulnerability was exploited in the wild. The EPSS score of 30.16% (96.60th percentile) indicates significant exploitation activity.

What products are affected by CVE-2020-8467?

CVE-2020-8467 affects Trend Micro Apex One version 2019 and Trend Micro OfficeScan XG. Both products contain a vulnerable migration tool component that allows remote code execution.

How do I fix CVE-2020-8467?

Apply the security patches from Trend Micro for Apex One 2019 and OfficeScan XG. Restrict network access to management interfaces and review authentication logs for suspicious activity. Ensure all instances are patched across the organization.

How severe is CVE-2020-8467?

CVE-2020-8467 has a CVSS 3.1 score of 8.8 (HIGH), enabling remote code execution on endpoint security management servers. Compromising these systems could disable security protections organization-wide, making this vulnerability particularly critical for enterprise environments.

CVSS Score

8.8
HIGH(8.8)

EPSS Score

EPSS Score10.79%
EPSS Percentile95.5%

Dates

PublishedMarch 18, 2020
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.