Input validation error in Trend Micro products - CVE-2020-8468
Published: March 18, 2020
Vulnerability details
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to a content validation escape issue. A remote authenticated attacker can pass specially crafted input to the application and manipulate certain agent client components.
Note: the vulnerability is being actively exploited in the wild.
Affected software
OfficeScan
Worry-Free Business Security
How to mitigate CVE-2020-8468
OfficeScan - addressed in versions XG CP 1988, XG SP1 CP 5474
Worry-Free Business Security - addressed in versions 9.5 B1525, 10.0 SP1 B2190