EXPOSURES › CVE-2019-18187
CVE-2019-18187
HIGH ⌖ ON CISA KEV · EXPLOITEDTrend Micro OfficeScan suffered a directory traversal vulnerability allowing remote code execution via zip file extraction.
Trend Micro OfficeScan allowed attackers to execute arbitrary code by exploiting a directory traversal flaw during zip file extraction. Defense contractors must ensure endpoint security tools are patched and monitored, as unpatched vulnerabilities in security software can be weaponized for lateral movement or ransomware deployment. Organizations should verify that all security products are on the latest patch level and that known CVEs are actively mitigated.
Shame score — A directory traversal vulnerability in a security product like OfficeScan is highly embarrassing because it undermines trust in the vendor's own security posture and allows attackers to bypass intended protections.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Trend Micro OfficeScan contains a directory traversal vulnerability by extracting files from a zip file to a specific folder on the OfficeScan server, leading to remote code execution.
"Trend Micro OfficeScan contains a directory traversal vulnerability by extracting files from a zip file to a specific folder on the OfficeScan server, leading to remote code execution."
"CISA's Known Exploited Vulnerabilities (KEV) catalog is the authoritative list of security flaws that have been confirmed exploited in real-world attacks."
| PRODUCT | STATUS |
|---|---|
| Trend Micro Cloud One for Government Trend Micro Inc. |
In Process |
| Trend Micro Vision One for Government Trend Micro Inc. |
In Process |