7.2

CVE-2021-25251

The Trend Micro Security 2020 and 2021 families of consumer products are vulnerable to a code injection vulnerability which could allow an attacker to disable the program's password protection and disable protection. An attacker must already have administrator privileges on the machine to exploit this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Antivirus+ Security 2020 Version 16.0
   Microsoft ≫ Windows Version -
Trendmicro ≫ Antivirus+ Security 2021 Version 17.0
   Microsoft ≫ Windows Version -
Trendmicro ≫ Internet Security 2020 Version 16.0
   Microsoft ≫ Windows Version -
Trendmicro ≫ Internet Security 2021 Version 17.0
   Microsoft ≫ Windows Version -
Trendmicro ≫ Maximum Security 2020 Version 16.0
   Microsoft ≫ Windows Version -
Trendmicro ≫ Maximum Security 2021 Version 17.0
   Microsoft ≫ Windows Version -
Trendmicro ≫ Premium Security 2020 Version 16.0
   Microsoft ≫ Windows Version -
Trendmicro ≫ Premium Security 2021 Version 17.0
   Microsoft ≫ Windows Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.49% 0.826
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.2 1.2 5.9
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
NIST 6.5 8 6.4
AV:N/AC:L/Au:S/C:P/I:P/A:P
CWE-94 Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

https://helpcenter.trendmicro.com/en-us/article/TMKA-10211
Vendor Advisory