LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2020-8467: Trend Micro Apex One and OfficeScan Remote Code Execution Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
May 3, 2022
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2020-8467 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of May 3, 2022 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Trend Micro Apex One and OfficeScan contain an unspecified vulnerability within a migration tool component that allows for remote code execution.

CVE-2020-8467 is a remote code execution vulnerability in Trend Micro Apex One and OfficeScan. It sits in a migration tool component and can let an attacker run code on affected systems if they can reach that component. For IT and security teams, this matters because endpoint security platforms often hold privileged access across many hosts; compromise of the management or migration path can expand quickly beyond a single machine.

Public detail on the exact weakness class is limited. Confirm affected builds, fixed versions, and any prerequisites against the vendor advisory before you act.

How it works

CISA describes an unspecified vulnerability in a migration tool component that allows remote code execution. In practical terms, that means an attacker who can interact with the vulnerable component may cause the product to execute attacker-controlled code in the context of the service or process that hosts the tool.

Because the CWE is not specified in the available record, defenders should treat this as a classic RCE in a privileged security product: successful abuse typically yields code execution with the rights of the Apex One or OfficeScan component involved. Do not assume a particular network path, authentication requirement, or exploit chain; those details must be taken from the vendor advisory. The important operational point is that migration-related functionality is in scope, so any exposure of that tooling—whether on management servers, during upgrades, or on endpoints still carrying the component—raises risk.

Am I affected? How to find it in your systems

Trend Micro Apex One and OfficeScan are endpoint protection and management products commonly deployed on Windows workstations and servers, with central managers or consoles in many environments. Inventory every host and management server that runs Apex One or OfficeScan, including residual or legacy OfficeScan installations and any systems still used for migration or upgrade workflows.

How to remediate

Patch first. Apply the updates Trend Micro released for this issue, following the vendor’s instructions exactly as CISA directs. Prioritize management servers and any systems that host or expose the migration tool component, then roll out to endpoints in a controlled wave.

If you can't patch immediately

Reduce exposure until you can install the vendor update.

If your data may have been exposed

Actively exploited remote code execution flaws in security products can lead to full host compromise and follow-on access to data or credentials on those systems. If you have evidence of exploitation or cannot rule it out, follow your incident response process: isolate affected hosts, preserve volatile and disk evidence, rotate credentials that may have been present, and assess lateral movement. Known ransomware use is not documented for this CVE in the provided facts; still treat confirmed RCE as a serious incident. You can run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in public breach corpora while you complete containment and recovery.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedTrend Micro · Apex One and OfficeScan
Added to CISA KEVNov 3, 2021
Federal patch deadlineMay 3, 2022
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities