CVE-2020-8467
Trendmicro Officescan xg
Raw vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HSummary
CVE-2020-8467 is a high-severity an unspecified weakness vulnerability in Trendmicro Officescan. Its CVSS base score is 8.8 (High).
Operationally, ranked in the top 5% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
CVE-2020-8467 is a remote code execution vulnerability in the migration tool component of Trend Micro Apex One (2019) and OfficeScan XG. The flaw received a CVSS v3.1 base score of 8.8 and is tracked without a specific CWE assignment.
An authenticated remote attacker can exploit the issue over the network without user interaction to execute arbitrary code on affected installations, resulting in full compromise of confidentiality, integrity, and availability on the target system.
Trend Micro has published official solutions addressing the vulnerability in the referenced advisories. The flaw also appears in CISA’s Known Exploited Vulnerabilities catalog, confirming observed in-the-wild exploitation.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2020-29333
Vulnerability Data
A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute arbitrary code on affected installations (RCE). An attempted attack requires user authentication.
- CWE(s)
- KEV Date Added
- 03 November 2021
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.