QID 375709
Date Published: 2021-07-19
QID 375709: Trend Micro Apex One(On-Prem) Multiple Vulnerabilities(000271974)(September 2020)
Trend Micro Apex One protection offers advanced automated threat detection and response against an ever-growing variety of threats, including file-less and ransomware.
CVE-2020-24563 - Trend Micro Apex One Authentication Bypass Vulnerability
CVE-2020-24564,CVE-2020-24565, CVE-2020-25770, CVE-2020-25771, CVE-2020-25772 -Trend Micro Apex One Out-of-Bounds Read Information Disclosure Vulnerabilities
CVE-2020-25773 - Trend Micro Apex One ServerMigrationTool DAT File Parsing Double Free Remote Code Execution Vulnerability
CVE-2020-25774 - Trend Micro Apex One ServerMigrationTool ZIP File Parsing Out-of-Bounds Read Information Disclosure Vulnerability
Affected Versions
Trend Micro Apex 2019(On-Prem)
QID Detection Logic:(Authenticated):
The QID checks for vulnerable version of Trend Micro Apex which it fetches out through registry file.
Note:Qualys does not support Apex One (SaaS).
Successful exploitation would allow an authenticated attacker to execute remote code and disclose sensitive information.
- 000271974 -
success.trendmicro.com/solution/000271974
CVEs related to QID 375709
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 000271974 |
|