Attacker Value
Moderate
(2 users assessed)
Exploitability
Moderate
(2 users assessed)
User Interaction
Unknown
Privileges Required
Unknown
Attack Vector
Unknown
1

CVE-2020-8467

Last updated April 14, 2020
Exploited in the Wild
Add MITRE ATT&CK tactics and techniques that apply to this CVE.

Description

Remote code execution vulnerability against Trend Micro Apex One (2019) and OfficeScan XG

Add Assessment

2
Ratings
Technical Analysis

Security products are notorious targets for attack because for them to perform their function, they must be elevated, so gaining execution means immediate execution as a privileged user. This CVE was discovered along with four other vulnerabilities after an internal review by Trend Micro Security Research:
CVE-2020-8468
CVE-2020-8470
CVE-2020-8598
CVE-2020-8599
There is evidence that this CVE (8467) and 8468 have exploit candidates that were seen in the wild. At this time, there are no PoCs that I could discover.

This CVE (8467) is an attack against a migration tool in Apex One and OfficeScan XG. The exact details are very murky, so it is hard to say what the remote attack surface is or how difficult it is to exploit. We can make some guesses as Trend Micro is relatively popular and remains a trusted enterprise security product.

1
Technical Analysis

Reported as exploited in the wild as part of Google’s 2020 0day vulnerability spreadsheet they made available at https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit#gid=1869060786. Original tweet announcing this spreadsheet with the 2020 findings can be found at https://twitter.com/maddiestone/status/1329837665378725888

General Information

Exploited in the Wild

Reported by:

Additional Info

Technical Analysis