Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-8470

Опубликовано: 18 мар. 2020
Источник: nvd
CVSS3: 7.5
CVSS2: 9.4
EPSS Низкий

Описание

Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow an attacker to delete any file on the server with SYSTEM level privileges. Authentication is not required to exploit this vulnerability.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:officescan:xg:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:officescan:xg:sp1:*:*:*:*:*:*
cpe:2.3:a:trendmicro:worry-free_business_security:9.0:sp3:*:*:*:*:*:*
cpe:2.3:a:trendmicro:worry-free_business_security:9.5:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:worry-free_business_security:10.0:-:*:*:*:*:*:*
cpe:2.3:a:trendmicro:worry-free_business_security:10.0:sp1:*:*:*:*:*:*

EPSS

Процентиль: 78%
0.01122
Низкий

7.5 High

CVSS3

9.4 Critical

CVSS2

Дефекты

NVD-CWE-noinfo

Связанные уязвимости

github
больше 3 лет назад

Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow an attacker to delete any file on the server with SYSTEM level privileges. Authentication is not required to exploit this vulnerability.

EPSS

Процентиль: 78%
0.01122
Низкий

7.5 High

CVSS3

9.4 Critical

CVSS2

Дефекты

NVD-CWE-noinfo