Skip to content
COOEY

EXPOSURES › CVE-2019-18187

CVE-2019-18187

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2019-18187 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Trend Micro OfficeScan suffered a directory traversal vulnerability allowing remote code execution via zip file extraction.

Trend Micro OfficeScan allowed attackers to execute arbitrary code by exploiting a directory traversal flaw during zip file extraction. Defense contractors must ensure endpoint security tools are patched and monitored, as unpatched vulnerabilities in security software can be weaponized for lateral movement or ransomware deployment. Organizations should verify that all security products are on the latest patch level and that known CVEs are actively mitigated.

Shame score — A directory traversal vulnerability in a security product like OfficeScan is highly embarrassing because it undermines trust in the vendor's own security posture and allows attackers to bypass intended protections.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Trend Micro OfficeScan contains a directory traversal vulnerability by extracting files from a zip file to a specific folder on the OfficeScan server, leading to remote code execution.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
Trend Micro's CVE-2019-18187 was confirmed as a critical directory traversal flaw enabling remote code execution, later listed in CISA's KEV catalog as actively exploited, reflecting severe fallout fo
cooey ↗ severe-fallout -0.80
NVD confirms critical RCE via directory traversal, indicating severe vulnerability severity.
"Trend Micro OfficeScan contains a directory traversal vulnerability by extracting files from a zip file to a specific folder on the OfficeScan server, leading to remote code execution."
cvefeed.io ↗ severe-fallout -0.50
CISA KEV catalog inclusion signals active exploitation, amplifying vendor fallout.
"CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks."
recentbreaches.com ↗ severe-fallout +0.00
No direct coverage of CVE-2019-18187; source is a breach tracker with unrelated 2026 ransomware listings.
app.opencve.io ↗ severe-fallout +0.00
No relevant CVE-2019-18187 data; source is a generic CVE search tool.
www.youtube.com ↗ severe-fallout +0.00
Irrelevant gaming content; no security coverage.
www.cvefind.com ↗ severe-fallout +0.00
No direct CVE-2019-18187 coverage; source is a CVE database with generic vendor lists.
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Trend Micro Cloud One for Government
Trend Micro Inc.
In Process
Trend Micro Vision One for Government
Trend Micro Inc.
In Process