← Vulnerability feed

Vulnerability record · CVE-2020-8599 · published 18 March 2020

CVE-2020-8599: Trend Micro Apex One and OfficeScan EXE allows arbitrary file write and ROOT bypass

Trendmicro · Apex One

Trend Micro Apex One (2019) and OfficeScan XG server ship a vulnerable EXE file that lets a remote, unauthenticated attacker write arbitrary data to an arbitrary path and bypass ROOT login. Because the flaw is reachable over the network with no credentials, it exposes the management server itself rather than just an endpoint agent.

9.8 CVSS 3.1 Critical CISA KEV since 3 Nov 2021 EPSS 12% · top 4.0%
9.8CVSS 3.1 base score, v2 10.0
12%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
2Affected product versions listed by NVD
5References
17 Jun 2026Last modified by NVD

Description

Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected installations and bypass ROOT login. Authentication is not required to exploit this vulnerability.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityCVSS 9.8 unauthenticated remote arbitrary file write plus ROOT bypass, confirmed exploited in CISA KEV, makes this a top remediation priority.

What it is

Trend Micro Apex One (2019) and OfficeScan XG server ship a vulnerable EXE file that lets a remote, unauthenticated attacker write arbitrary data to an arbitrary path and bypass ROOT login. Because the flaw is reachable over the network with no credentials, it exposes the management server itself rather than just an endpoint agent.

Impact

An attacker can write files anywhere on the server and bypass ROOT authentication, which in practice yields full control of the affected installation. That control can be used to disable protection, alter configuration, or stage further compromise of managed endpoints.

Attack surface

Reachable over the network (AV:N) with no privileges (PR:N) and no user interaction (UI:N) per the CVSS vector. The description states authentication is not required, so the vulnerable EXE is exposed to unauthenticated remote requests.

Exploitation

It is listed in CISA KEV (added 2021-11-03, due 2022-05-03), confirming exploitation in the wild; EPSS 30-day probability is about 11.9% (95.9th percentile). No ransomware campaign use is recorded in the KEV entry.

What to do

  • Apply the vendor patches referenced in the Trend Micro advisories (solution 000245571 and 000244253) as the first action.
  • If patching cannot be done immediately, restrict network access to the Apex One/OfficeScan server management interfaces to trusted administrative networks only.
  • Audit and rotate administrative and ROOT credentials for the affected servers, since ROOT login bypass is part of the flaw.
  • Monitor the server for unexpected file writes and new or modified executables in system and application paths.
  • Verify the server has not been modified before returning it to production, and reimage if compromise is suspected.

Detection

  • Hunt for unexpected file creation or modification in server system directories and application install paths on Apex One/OfficeScan hosts.
  • Alert on successful ROOT or administrative logins to the management server that do not match known admin source IPs or schedules.
  • Review server logs for unauthenticated requests to the vulnerable EXE and for anomalous process execution spawned by the management service.
  • Correlate file-write events with subsequent service restarts or configuration changes on the affected server.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2020-8599 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Trend Micro Apex One and OfficeScan Authentication Bypass Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 3 May 2022.

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-8599 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2025-54948Trend Micro Apex One management console OS command injectionThe on-premise Apex One management console contains an OS command injection flaw (CWE-78) that lets a remote attacker upload malicious code and run c…KEVEPSS 22%analysed9.8CVE-2022-26871Trend Micro Apex Central unauthenticated arbitrary file uploadTrend Micro Apex Central (and Apex One) contains an arbitrary file upload flaw caused by insufficient verification of data authenticity (CWE-345). An…KEVEPSS 19%analysed8.8CVE-2021-36741Trend Micro Apex One and OfficeScan unrestricted file uploadTrend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 fail to properly validate input, allowing an aut…KEVEPSS 5.0%analysed8.8CVE-2020-8468Trend Micro Apex One, OfficeScan and Worry-Free agents content validation escapeTrend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents contain a content validation escape flaw (CWE-74)…KEVEPSS 6.2%analysed8.8CVE-2020-8467Trend Micro Apex One and OfficeScan migration tool RCEA component of the migration tool in Trend Micro Apex One (2019) and OfficeScan XG allows remote attackers to execute arbitrary code on affected inst…KEVEPSS 11%analysed7.8CVE-2021-36742Trend Micro Apex One and OfficeScan improper input validation privilege escalationTrend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 contain an improper input validation flaw (CWE-2…KEVEPSS 1.5%analysed7.8CVE-2020-24557Trend Micro Apex One and Worry-Free Business Security folder manipulation privilege escalationTrend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Windows allow an attacker to manipulate a product folder to temporarily disable the…KEVEPSS 2.7%analysed7.5CVE-2019-18187Trend Micro OfficeScan directory traversal enables remote code executionTrend Micro OfficeScan 11.0 and XG (12.0) contain a directory traversal flaw (CWE-22) that lets an attacker extract files from an arbitrary zip archi…KEVEPSS 25%analysed

Source: NIST National Vulnerability Database (record CVE-2020-8599), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.