SecPod

Learn Search

Search across all Learn content

← Back to Security Research
Active exploitation of zero-days in Trend Micro security products

Active exploitation of zero-days in Trend Micro security products

Mar 17, 2020By Vidita V Koushik2 min read

Recent attacks involved the exploitation of security holes in Trend Micro’s enterprise security products. Trend Micro issued a critical security advisory stating that it has observed active attempts of potential attacks against its products.

In-the-wild zer0-day exploits

  • CVE-2020-8467 is a critical remote code execution vulnerability in the migration tool component of Trend Micro Apex One and OfficeScan.
  • CVE-2020-8468 is a high severity content validation escape vulnerability in Trend Micro Apex One and OfficeScan agents. This bug allows an attacker to manipulate certain agent client components.

The two zero-days require user authentication for exploitation, and therefore we can infer that the attacks using these bugs must have been carried out in networks that the attackers have previously gained a foothold in. These bugs have most likely been used to elevate existing privileges or disable security products running in enterprise environments.

Other Critical Vulnerabilities

  • CVE-2020-8470 : A flaw exists in the DLL file of a vulnerable service that allows attackers to delete any file on the server with SYSTEM level privileges.
  • CVE-2020-8598 : A flaw exists in the DLL file of a vulnerable service that allows attackers to execute arbitrary code on vulnerable installations with SYSTEM level privileges.
  • CVE-2020-8599: A flaw exists in a vulnerable EXE file which allows attackers to write arbitrary data to an arbitrary path on vulnerable installations and bypass ROOT login.

All three vulnerabilities have been rated critical with a CVSS score of 10.0 and do not require authentication for their exploitation. However, there have been no reports of active exploitation of these bugs so far.

Impact

The exploitation of these critical vulnerabilities could allow attackers to execute arbitrary code, bypass security mechanisms and modify sensitive components on target systems.

Affected Products

  • Trend Micro Apex One (on premise) version 2019
  • Trend Micro OfficeScan version XG SP1 and XG (non-SP)

Solution

Trend Micro has released critical security fixes for these vulnerabilities. The fixes are available in:

We strongly recommend installing these security updates without any delay.

Featured Posts

Open Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212
Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE Research

Root-Level RCE Flaw in Cisco Nexus 9000 Series Switches Exposes Networks to Complete Compromise — CVE-2026-20212

CVE-2026-20212 is a critical vulnerability in Cisco Nexus 9000 Series Switches that use Silicon One ASICs. It allows an unauthenticated remote attacker to execute code with root privileges by sending crafted input to TCP ports 43210 and 43211, which are reachable in the default Layer 3 VRF. Exploitation can also crash the S1HAL process and force a device reload. This article covers how the vulnerability works, the affected product identifiers, its potential impact, available workarounds, and how to identify fixed software using the Cisco Software Checker.

Sep 4, 2026

Open SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution
SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

CVE Research

SonicWall SMA 1000 Under Active Attack: Two Zero-Days Enable SSRF and Remote Code Execution

Sep 3, 2026

Open Introducing SecPod VEX Studio: Guided Vulnerability Exploitability Assessment for Open-Source Maintainers
Secpod_VEX_Studio For Open-Source Vulnerability Management

CVE Research

Introducing SecPod VEX Studio: Guided Vulnerability Exploitability Assessment for Open-Source Maintainers

A human-guided path from SBOM and vulnerability data to reviewable OpenVEX statements

Sep 2, 2026

Open Inside the PaperCut Zero-Day Attack Chain: Auth Bypass to Code Execution
Inside the PaperCut Zero-Day Attack Chain: Auth Bypass to Code Execution

CVE Research

Inside the PaperCut Zero-Day Attack Chain: Auth Bypass to Code Execution

Sep 1, 2026