CVE-2020-8468

ENISA EUVD: EUVD-2020-29334 ↗
Exploited in the Wild ✓ Confirmed 0-Day ★ Google Project Zero
Triaged: March 3, 2026 1 article

EPSS Score

Source: FIRST.org · 2026-05-24
19.09%
probability
This CVE has a 19.09% probability of being exploited in the next 30 days.
0% Top 95.4th percentile of all CVEs 100%

CVSS v3.1

Source: NVD
8.8
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

Project Zero
Content validation escape in agent client component

Affected Products

Google Project Zero

Patched
March 16, 2020
Reported by
Trend Micro Research
Root Cause Analysis
???
Security Advisory 2020-016
CERT-EU Mar 18, 2020

Signal Intelligence

Confidence
78%
EPSS 19.09%
CVSS v3.1 8.8
Mentions 1
Last Seen Mar 18, 2020

CNA Information

Analyst Note

CVE-2020-8468 is confirmed as a legitimate vulnerability affecting multiple Trend Micro products with a HIGH CVSS score (8.8) and validation from CERT-EU advisory. The vulnerability requires user authentication and involves content validation escape in agent components, reducing exploitability but confirming the threat's authenticity.

Triage Info

Decided atMar 03, 2026