Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected installations and bypass ROOT login. Authentication is not required to exploit this vulnerability.
Link | Tags |
---|---|
https://success.trendmicro.com/solution/000245571 | patch vendor advisory |
https://success.trendmicro.com/jp/solution/000244253 | patch vendor advisory |