5.5

CVE-2021-25252

Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Apex Central Version 2019 Update -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex One Version 2019 Update -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Cloud Edge Version 5.0
Trendmicro ≫ Apex One Version - Update -
   Apple ≫ macOS Version -
Trendmicro ≫ Deep Security Version 10.0 Update -
Trendmicro ≫ Deep Security Version 11.0 Update -
Trendmicro ≫ Deep Security Version 12.0 Update -
Trendmicro ≫ Deep Security Version 20.0 Update - SwEdition long_term_support
Trendmicro ≫ Control Manager Version 7.0 Update -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Deep Discovery Analyzer Version 5.1 Update -
Trendmicro ≫ Deep Discovery Email Inspector Version 2.5 Update -
Trendmicro ≫ Deep Discovery Inspector Version 3.8 Update -
Trendmicro ≫ Officescan Version -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Portal Protect Version 2.6
   Microsoft ≫ Windows Version -
Trendmicro ≫ Scanmail Version 14.0 SwPlatform microsoft_exchange
   Microsoft ≫ Windows Version -
Trendmicro ≫ Scanmail For Ibm Domino Version 5.8 Update -
   Linux ≫ Linux Kernel Version -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Serverprotect For Storage Version 6.0 Update -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Serverprotect Version 5.8 Update -
   Emc ≫ Celerra Network Attached Storage Version -
   Microsoft ≫ Windows Version -
   Novell ≫ Netware Version -
Trendmicro ≫ Safe Lock Version 1.1 Update - SwEdition txone
   Microsoft ≫ Windows Version -
Trendmicro ≫ Worry-free Business Security Version 10.1 Update -
   Microsoft ≫ Windows Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.56% 0.419
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.5 1.8 3.6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
NIST 4.9 3.9 6.9
AV:L/AC:L/Au:N/C:N/I:N/A:C
CWE-400 Uncontrolled Resource Consumption

The product does not properly control the allocation and maintenance of a limited resource.

https://success.trendmicro.com/solution/000285675
Patch
Vendor Advisory