CVE-2020-8468: Trend Micro Multiple Products Content Validation Escape Vulnerability
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent client components. An attempted attack requires user authentication.
Other sources
Trend Micro Apex One, OfficeScan, and Worry-Free Business Security agents contain a content validation escape vulnerability that could allow an attacker to manipulate certain agent client components.
— CISA
Affected Software
Remediation
Patch Available
Patch Available
Patch Available
Patch Available
Event History
Frequently Asked Questions
What is CVE-2020-8468?
CVE-2020-8468 is a vulnerability known as Trend Micro Multiple Products Content Validation Escape Vulnerability.
Which products are affected by CVE-2020-8468?
Trend Micro Apex One (2019), OfficeScan XG, and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by CVE-2020-8468.
What is the severity of CVE-2020-8468?
CVE-2020-8468 has a severity rating of 8.8, which is considered high.
How can an attacker exploit CVE-2020-8468?
An attacker can exploit CVE-2020-8468 by manipulating certain agent client components, but authentication is required.
How can I fix CVE-2020-8468?
To fix CVE-2020-8468, it is recommended to apply the necessary security patches or updates provided by Trend Micro.