# Multiple vulnerabilities in Trend Micro products allow remote code execution and…

Published: 2020-03-15 · Severity: critical
Canonical: https://vorant.io/reports/bb01abb2-c43d-480b-b5bb-725b55eb8033/multiple-vulnerabilities-in-trend-micro-products-allow-remote-code-execution-and

> Multiple vulnerabilities in Trend Micro products allow remote code execution and component tampering; CVE-2020-8467 and CVE-2020-8468 actively exploited.

Japan's IPA has issued an alert regarding multiple vulnerabilities discovered in products provided by Trend Micro. The vulnerabilities enable remote attackers to execute arbitrary code or tamper with system components. Two specific vulnerabilities, CVE-2020-8467 and CVE-2020-8468, are of particular concern as active exploitation has already been confirmed in the wild. IPA warns that damage from these vulnerabilities may expand and urges immediate remediation. The agency recommends that users apply patches provided by Trend Micro as soon as possible. Details are available through the IPA Security Center, though they note they cannot respond to questions about individual systems and environments.

## Mentioned in this report

- Vulnerabilities: CVE-2020-8467 (KEV), CVE-2020-8468 (KEV)

Source reporting: https://www.ipa.go.jp/archive/security/security-alert/2019/alert20200316.html

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/bb01abb2-c43d-480b-b5bb-725b55eb8033/multiple-vulnerabilities-in-trend-micro-products-allow-remote-code-execution-and.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
