← Back to browse · API

CVE-2019-18187

Severity
HIGH
CVSS
8.8
EPSS
0.25125
Risk score
68.99
CISA KEV
Yes
PoC
No
Published
2019-10-28
Modified
2025-10-29
First seen
2026-08-07
Aliases
EUVD-2019-7990, GHSA-CJQ6-9JH6-X2VG
Products
Trend Micro:OfficeScan, Trend Micro:Trend Micro OfficeScan Version 11.0, XG (12.0)
Sources
euvd EUVD-2019-7990
cisa.gov CVE-2019-18187

Description

Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extract files from an arbitrary zip file to a specific folder on the OfficeScan server, which could potentially lead to remote code execution (RCE). The remote process execution is bound to a web service account, which depending on the web platform used may have restricted permissions. An attempted attack requires user authentication.

References