HIGH

CVE-2021-36741

Trendmicro Officescan 2021-07-29 CVSS v3.1
CVSS
8.8
KEV

Description

An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the ability to logon to the product�s management console in order to exploit this vulnerability.

Summary dbcve.org

Improper input validation in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows authenticated users to bypass file upload restrictions and upload arbitrary files to the management console, potentially leading to remote code execution.

Mitigation

Apply vendor-provided patches for this vulnerability. Restrict and monitor access to the management console, enforce strong credential policies, and disable unnecessary file upload features if not required.

Weakness (CWE)

CWE-434 Unrestricted File Upload

EPSS Score

4.95%
Probability of exploitation in next 30 days
91.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE