CVE-2021-36741
Description
An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the ability to logon to the product�s management console in order to exploit this vulnerability.
Summary dbcve.org
Improper input validation in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows authenticated users to bypass file upload restrictions and upload arbitrary files to the management console, potentially leading to remote code execution.
Mitigation
Apply vendor-provided patches for this vulnerability. Restrict and monitor access to the management console, enforce strong credential policies, and disable unnecessary file upload features if not required.