HIGH

CVE-2021-36742

Trendmicro Officescan 2021-07-29 CVSS v3.1
CVSS
7.8
KEV

Description

A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

Summary dbcve.org

This is a local privilege escalation vulnerability caused by improper input validation in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1. An attacker who has already achieved low-privileged code execution on the target system can exploit improper input validation to elevate their privileges to higher levels.

Mitigation

Apply the vendor-supplied security patches or updates for the affected Trend Micro products as soon as they become available, after appropriate testing in a non-production environment.

Weakness (CWE)

CWE-20 Improper Input Validation

EPSS Score

1.48%
Probability of exploitation in next 30 days
72.8th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE