SB2019102814 - Path traversal in OfficeScan



SB2019102814 - Path traversal in OfficeScan

Published: October 28, 2019 Updated: August 8, 2020

Security Bulletin ID SB2019102814
Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 security vulnerability.


1) Path traversal (CVE-ID: CVE-2019-18189)

The vulnerability allows a remote non-authenticated attacker to execute arbitrary code.

A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker to bypass authentication and log on to an affected product's management console as a root user. The vulnerability does not require authentication.


Remediation

Install update from vendor's website.