#VU35143 Path traversal in OfficeScan and Worry-Free Business Security - CVE-2019-18189
Published: October 28, 2019 / Updated: August 8, 2020
OfficeScan
Worry-Free Business Security
Trend Micro
Description
The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.
A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker to bypass authentication and log on to an affected product's management console as a root user. The vulnerability does not require authentication.