Skip to content
COOEY

EXPOSURES › CVE-2020-8467

CVE-2020-8467

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-8467 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 rceexploited-in-wildunpatched

Trend Micro Apex One and OfficeScan suffered a remote code execution vulnerability in a migration tool component that was actively exploited in the wild.

The vulnerability allowed attackers to execute arbitrary code remotely through an unspecified flaw in a migration tool component. This is a critical failure for DIB organizations relying on Trend Micro for endpoint protection, as it directly compromises system integrity and violates CMMC/NIST 800-171 requirements for patch management and vulnerability mitigation. Organizations must verify patch levels and consider alternative vendors if the vulnerability remains unpatched.

Shame score — A remote code execution vulnerability in a widely deployed endpoint security product was actively exploited in the wild, indicating a failure to patch a known or discoverable flaw before malicious actors could weaponize it.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Trend Micro Apex One and OfficeScan contain an unspecified vulnerability within a migration tool component that allows for remote code execution.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
CVE-2020-8467 represents a critical remote code execution flaw in Trend Micro's migration tool, exposing Apex One and OfficeScan to severe compromise risks. The NVD entry confirms the severity without
cooey ↗ severe-fallout -0.60
Critical RCE vulnerability in migration tool component exposes Apex One and OfficeScan to remote code execution, indicating a severe security oversight in Trend Micro's product design and deployment.
"Trend Micro Apex One and OfficeScan contain an unspecified vulnerability within a migration tool component that allows for remote code execution."
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Trend Micro Cloud One for Government
Trend Micro Inc.
In Process
Trend Micro Vision One for Government
Trend Micro Inc.
In Process