Show filters
108 Total Results
Displaying 41-50 of 108
Sort by:
Attacker Value
Unknown
CVE-2020-8599
Disclosure Date: March 18, 2020 (last updated November 27, 2024)
Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected installations and bypass ROOT login. Authentication is not required to exploit this vulnerability.
0
Attacker Value
Unknown
CVE-2020-8598
Disclosure Date: March 18, 2020 (last updated February 21, 2025)
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow a remote attacker to execute arbitrary code on affected installations with SYSTEM level privileges. Authentication is not required to exploit this vulnerability.
0
Attacker Value
Unknown
CVE-2019-14688
Disclosure Date: February 20, 2020 (last updated February 21, 2025)
Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product installation. The vulnerability was found to ONLY be exploitable during an initial product installation by an authorized user. The attacker must convince the target to download malicious DLL locally which must be present when the installer is run.
0
Attacker Value
Unknown
CVE-2019-19694
Disclosure Date: February 20, 2020 (last updated November 27, 2024)
The Trend Micro Security 2019 (15.0.0.1163 and below) consumer family of products is vulnerable to a denial of service (DoS) attack in which a malicious actor could manipulate a key file at a certain time during the system startup process to disable the product's malware protection functions or the entire product completely..
0
Attacker Value
Unknown
CVE-2019-19691
Disclosure Date: December 20, 2019 (last updated November 27, 2024)
A vulnerability in Trend Micro Apex One and OfficeScan XG could allow an attacker to expose a masked credential key by manipulating page elements using development tools. Note that the attacker must already have admin/root privileges on the product console to exploit this vulnerability.
0
Attacker Value
Unknown
CVE-2019-18189
Disclosure Date: October 28, 2019 (last updated November 27, 2024)
A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker to bypass authentication and log on to an affected product's management console as a root user. The vulnerability does not require authentication.
0
Attacker Value
Unknown
CVE-2019-9492
Disclosure Date: July 26, 2019 (last updated November 27, 2024)
A DLL side-loading vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow an authenticated attacker to gain code execution and terminate the product's process - disabling endpoint protection. The attacker must have already gained authentication and have local access to the vulnerable system.
0
Attacker Value
Unknown
CVE-2019-9489
Disclosure Date: April 05, 2019 (last updated November 27, 2024)
A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (versions XG and 11.0), and Worry-Free Business Security (versions 10.0, 9.5 and 9.0) could allow an attacker to modify arbitrary files on the affected product's management console.
0
Attacker Value
Unknown
CVE-2018-18331
Disclosure Date: December 21, 2018 (last updated November 27, 2024)
A Trend Micro OfficeScan XG weak file permissions vulnerability on a particular folder for a particular group may allow an attacker to alter the files, which could lead to other exploits on vulnerable installations.
0
Attacker Value
Unknown
CVE-2018-18332
Disclosure Date: December 21, 2018 (last updated November 27, 2024)
A Trend Micro OfficeScan XG weak file permissions vulnerability may allow an attacker to potentially manipulate permissions on some key files to modify other files and folders on vulnerable installations.
0