HIGH KEV
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent client components
Published Mar 18, 2020 ·Due May 3, 2022
8.8
HIGHCVSS 3.1
EPSS 6.17%
Description
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent client components. An attempted attack requires user authentication.
Affected products
-
- Version OfficeScan XG (12.0), Apex One 2019 (14.0), WFBS 9.0, 9.5 and 10.0StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Trend Micro | n/a | n/a |
|
OR
- 2019
- xg
- xg
- 9.0
- 9.5
- 10.0
- 10.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29334 Advisory
- https://success.trendmicro.com/jp/solution/000244253 x_refsource_MISCPatchVendor Advisory
- https://success.trendmicro.com/jp/solution/000244836 x_refsource_MISCPatchVendor Advisory
- https://success.trendmicro.com/solution/000245571 x_refsource_MISCPatchVendor Advisory
- https://success.trendmicro.com/solution/000245572 x_refsource_MISCPatchVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8468 government-resourceUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2020-29334 | Advisory | |
| https://success.trendmicro.com/jp/solution/000244253 | x_refsource_MISCPatchVendor Advisory | |
| https://success.trendmicro.com/jp/solution/000244836 | x_refsource_MISCPatchVendor Advisory | |
| https://success.trendmicro.com/solution/000245571 | x_refsource_MISCPatchVendor Advisory | |
| https://success.trendmicro.com/solution/000245572 | x_refsource_MISCPatchVendor Advisory | |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2020-8468 | government-resourceUS Government Resource |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner trendmicro
Published Mar 18, 2020
Updated Oct 21, 2025
Reserved Jan 30, 2020
Link CVE-2020-8468
CISA Vulnrichment
EUVD-2020-29334 Updated Feb 6, 2025