7.8
CVE-2021-36742
- EPSS 1.48%
- Veröffentlicht 29.07.2021 20:15:07
- Zuletzt bearbeitet 31.10.2025 17:14:09
- Erkennungen
A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Officescan Version xg Update sp1
Trendmicro ≫ Officescan Business Security Version 10.0 Update sp1
Trendmicro ≫ Apex One Version 2019
Trendmicro ≫ Worry-free Business Security Version 10.0 Update sp1
03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog
Trend Micro Multiple Products Improper Input Validation Vulnerability
SchwachstelleTrend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows for privilege escalation.
BeschreibungApply updates per vendor instructions.
Erforderliche Maßnahmen| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.48% | 0.706 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
| NIST | 4.6 | 3.9 | 6.4 |
AV:L/AC:L/Au:N/C:P/I:P/A:P
|
| CISA-ADP | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-20 Improper Input Validation
The product receives input or data, but it does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.
https://success.trendmicro.com/jp/solution/000287796
https://success.trendmicro.com/jp/solution/000287815
https://success.trendmicro.com/solution/000287819
https://success.trendmicro.com/solution/000287820
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-36742