EXPOSURES › CVE-2020-8467
CVE-2020-8467
HIGH ⌖ ON CISA KEV · EXPLOITEDTrend Micro Apex One and OfficeScan suffered a remote code execution vulnerability in a migration tool component that was actively exploited in the wild.
The vulnerability allowed attackers to execute arbitrary code remotely through an unspecified flaw in a migration tool component. This is a critical failure for DIB organizations relying on Trend Micro for endpoint protection, as it directly compromises system integrity and violates CMMC/NIST 800-171 requirements for patch management and vulnerability mitigation. Organizations must verify patch levels and consider alternative vendors if the vulnerability remains unpatched.
Shame score — A remote code execution vulnerability in a widely deployed endpoint security product was actively exploited in the wild, indicating a failure to patch a known or discoverable flaw before malicious actors could weaponize it.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Trend Micro Apex One and OfficeScan contain an unspecified vulnerability within a migration tool component that allows for remote code execution.
"Trend Micro Apex One and OfficeScan contain an unspecified vulnerability within a migration tool component that allows for remote code execution."
| PRODUCT | STATUS |
|---|---|
| Trend Micro Cloud One for Government Trend Micro Inc. |
In Process |
| Trend Micro Vision One for Government Trend Micro Inc. |
In Process |