CVE-2021-36741
Trend Micro Multiple Products Improper Input Validation Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 17 November 2021). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the ability to logon to the product�s management console in order to exploit this vulnerability.
- CVSS 3.1
- 8.8 HIGHCVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.95% probability · 92th percentile
- CISA KEV
- Listed 3 November 2021 · due 17 November 2021
- Weakness
- CWE-434
- Affected
- trendmicro/officescan · trendmicro/officescan business security · trendmicro/apex one · trendmicro/worry-free business security
- Source
- security@trendmicro.com
CISA notes
Apply updates per vendor instructions. https://success.trendmicro.com/dcx/s/solution/000287819?language=en_US, https://success.trendmicro.com/dcx/s/solution/000287820?language=en_US; https://nvd.nist.gov/vuln/detail/CVE-2021-36741
References
- https://success.trendmicro.com/jp/solution/000287796Broken Link, Vendor Advisory
- https://success.trendmicro.com/jp/solution/000287815Broken Link, Vendor Advisory
- https://success.trendmicro.com/solution/000287819Broken Link, Vendor Advisory
- https://success.trendmicro.com/solution/000287820Broken Link, Vendor Advisory
- https://success.trendmicro.com/jp/solution/000287796Broken Link, Vendor Advisory
- https://success.trendmicro.com/jp/solution/000287815Broken Link, Vendor Advisory
- https://success.trendmicro.com/solution/000287819Broken Link, Vendor Advisory
- https://success.trendmicro.com/solution/000287820Broken Link, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-36741US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.