7.8
CVE-2021-25249
- EPSS 0.43%
- Veröffentlicht 04.02.2021 20:15:14
- Zuletzt bearbeitet 21.11.2024 05:54:37
- Erkennungen
An out-of-bounds write information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Apex One Version 2019
Trendmicro ≫ Officescan Version xg Update sp1
Trendmicro ≫ Worry-free Business Security Version 10.0 Update sp1
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.43% | 0.339 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 7.2 | 3.9 | 10 |
AV:L/AC:L/Au:N/C:C/I:C/A:C
|
CWE-787 Out-of-bounds Write
The product writes data past the end, or before the beginning, of the intended buffer.
https://success.trendmicro.com/solution/000284202
https://success.trendmicro.com/solution/000284205
https://success.trendmicro.com/solution/000284206
https://www.zerodayinitiative.com/advisories/ZDI-21-119/