Critical severity9.8CISA KEVNVD Advisory· Published Mar 18, 2020· Updated Jun 17, 2026
CVE-2020-8599
CVE-2020-8599
Description
Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected installations and bypass ROOT login. Authentication is not required to exploit this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:*:*:*:*
- (no CPE)range: 2019
cpe:2.3:a:trendmicro:officescan:xg:-:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:trendmicro:officescan:xg:-:*:*:*:*:*:*
- cpe:2.3:a:trendmicro:officescan:xg:sp1:*:*:*:*:*:*
- (no CPE)
- Trend Micro/Trend Micro OfficeScan, Trend Micro Apex Onev5Range: OfficeScan XG (12.0), Apex One 2019 (14.0)
Patches
Vulnerability mechanics
References
3- success.trendmicro.com/jp/solution/000244253nvdBroken LinkPatchVendor Advisory
- success.trendmicro.com/solution/000245571nvdBroken LinkPatchVendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalognvdUS Government Resource
News mentions
0No linked articles in our index yet.