CVE-2020-25773

HIGH

Trend Micro Apex One - Remote Code Execution via Corrupted Configuration File Import

Title source: llm
STIX 2.1

Description

A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to execute arbitrary code on affected products. User interaction is required to exploit this vulnerability in that the target must import a corrupted configuration file.

References (2)

Core 2
Core References
Vendor Advisory x_refsource_misc
https://success.trendmicro.com/solution/000271974
Third Party Advisory, VDB Entry x_refsource_misc
https://www.zerodayinitiative.com/advisories/ZDI-20-1224/

Scores

CVSS v3 7.8
EPSS 0.0053
EPSS Percentile 67.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-415
Status published
Products (2)
trendmicro/apex_one 2019
trendmicro/apex_one saas
Published Sep 29, 2020
Tracked Since Feb 18, 2026