CVE Database
/

CVE-2019-18187

Back to search

CVE-2019-18187

Published: Oct 28, 2019

Modified: Oct 29, 2025

PUBLISHED

Description

Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extract files from an arbitrary zip file to a specific folder on the OfficeScan server, which could potentially lead to remote code execution (RCE). The remote process execution is bound to a web service account, which depending on the web platform used may have restricted permissions. An attempted attack requires user authentication.

VendorProductVersions

Trend Micro

Trend Micro OfficeScan

affected
Version 11.0, XG (12.0)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now