Skip to content
COOEY

EXPOSURES › CVE-2020-8599

CVE-2020-8599

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2021-11-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2020-8599 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 78/100 exploited-in-wildunpatchedrcesupply-chain

Trend Micro Apex One and OfficeScan servers suffered an authentication bypass allowing remote attackers to write data and bypass root login.

The vulnerability in Trend Micro Apex One and OfficeScan allowed remote attackers to bypass authentication and write data to arbitrary paths, potentially leading to full system compromise. DIB organizations must ensure these endpoints are patched immediately, as the flaw was actively exploited in the wild and represents a significant supply-chain and endpoint security failure. Failure to patch exposes critical endpoint management systems to unauthorized access and data exfiltration.

Shame score — A critical authentication bypass in a widely deployed endpoint security product was actively exploited in the wild, demonstrating severe negligence in patch management and vulnerability disclosure.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Trend Micro Apex One and OfficeScan server contain a vulnerable EXE file that could allow a remote attacker to write data to a path on affected installations and bypass root login.

SENTIMENT · TRUSTED SOURCES
synthesis severe-fallout -0.60
CVE-2020-8599 represents a critical authentication bypass vulnerability in Trend Micro's Apex One and OfficeScan, allowing remote attackers to write data and bypass root login. The provided sources la
cooey ↗ severe-fallout -0.80
NVD entry confirms the critical nature of the authentication bypass vulnerability, allowing remote attackers to write data and bypass root login, which is a severe security failure.
"Trend Micro Apex One and OfficeScan server contain a vulnerable EXE file that could allow a remote attacker to write data to a path on affected installations and bypass root login."
recentbreaches.com ↗ severe-fallout +0.00
No specific commentary on CVE-2020-8599 or Trend Micro; the site is a general breach tracker with no vendor-specific sentiment.
NIST ↗ severe-fallout +0.00
NVD homepage; no specific commentary on CVE-2020-8599 or Trend Micro.
xposedornot.com ↗ severe-fallout +0.00
Breach directory homepage; no specific commentary on CVE-2020-8599 or Trend Micro.
SentinelOne ↗ severe-fallout +0.00
SentinelOne vulnerability database homepage; no specific commentary on CVE-2020-8599 or Trend Micro.
AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Trend Micro Cloud One for Government
Trend Micro Inc.
In Process
Trend Micro Vision One for Government
Trend Micro Inc.
In Process