CVE-2020-8600: Trend Micro Worry-Free Business Security Directory Traversal Authentication Bypass Vulnerability
Published Mar 18, 2020
·Updated
Trend Micro Worry-Free Business Security (9.0, 9.5, 10.0) is affected by a directory traversal vulnerability that could allow an attacker to manipulate a key file to bypass authentication.
Affected Software
4 affected components
trendmicro Worry-free Business Security=9.0-sp3
trendmicro Worry-free Business Security=9.5
trendmicro Worry-free Business Security=10.0
trendmicro Worry-free Business Security=10.0-sp1
Remediation
Patch Available
Patch Available
Event History
Mar 18, 2020
CVE Published
via MITRE·12:30 AM
Data Sourced
via MITRE·12:30 AM
DescriptionWeakness
Data Sourced
via NVD·01:15 AM
RemedyDescriptionSeverityWeaknessAffected Software
Jun 29, 2026
Advisory Published
via ZDI·03:43 AM
Data Sourced
via ZDI·03:43 AM
DescriptionAffected Software
Frequently Asked Questions
1
What is CVE-2020-8600?
CVE-2020-8600 is a vulnerability in Trend Micro Worry-Free Business Security that allows remote attackers to bypass authentication.
2
How severe is CVE-2020-8600?
CVE-2020-8600 is classified as critical with a severity value of 9.8.
3
Which software versions are affected by CVE-2020-8600?
CVE-2020-8600 affects Trend Micro Worry-Free Business Security versions 9.0 SP3, 9.5, 10.0, and 10.0 SP1.
4
How can I exploit CVE-2020-8600?
Exploiting CVE-2020-8600 does not require authentication and involves manipulating the TempFileName parameter in the cgiRecvF function.
5
How can I fix CVE-2020-8600?
To fix CVE-2020-8600, update Trend Micro Worry-Free Business Security to the latest version provided by the vendor.