PT-2020-1932 · Trend Micro · Trend Micro Worry-Free Business Security

Published

2020-03-16

·

Updated

2020-03-20

·

CVE-2020-8600

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Trend Micro Worry-Free Business Security versions 9.0 through 10.0
Description The issue exists due to insufficient input validation of the TempFileName parameter in the cgiRecvFile.exe executable of Trend Micro Worry-Free Business Security. This could allow a remote attacker to read arbitrary files on the target system by sending specially crafted HTTP requests. The vulnerability may also enable an attacker to manipulate a key file, potentially bypassing authentication.
Recommendations For versions 9.0 through 10.0, update to a version that includes a fix for this issue to prevent exploitation. As a temporary workaround, consider restricting access to the cgiRecvFile.exe executable until a patch is available. Avoid using the TempFileName parameter in affected HTTP requests until the issue is resolved.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-01209
CVE-2020-8600
ZDI-20-307

Affected Products

Trend Micro Worry-Free Business Security