CVE-2021-36742
Trend Micro Multiple Products Improper Input Validation Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 17 November 2021). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 1.48% probability · 72th percentile
- CISA KEV
- Listed 3 November 2021 · due 17 November 2021
- Weakness
- CWE-20
- Affected
- trendmicro/officescan · trendmicro/officescan business security · trendmicro/apex one · trendmicro/worry-free business security
- Source
- security@trendmicro.com
CISA notes
Apply updates per vendor instructions. https://success.trendmicro.com/dcx/s/solution/000287819?language=en_US, https://success.trendmicro.com/dcx/s/solution/000287820?language=en_US; https://nvd.nist.gov/vuln/detail/CVE-2021-36742
References
- https://success.trendmicro.com/jp/solution/000287796Vendor Advisory
- https://success.trendmicro.com/jp/solution/000287815Vendor Advisory
- https://success.trendmicro.com/solution/000287819Vendor Advisory
- https://success.trendmicro.com/solution/000287820Vendor Advisory
- https://success.trendmicro.com/jp/solution/000287796Vendor Advisory
- https://success.trendmicro.com/jp/solution/000287815Vendor Advisory
- https://success.trendmicro.com/solution/000287819Vendor Advisory
- https://success.trendmicro.com/solution/000287820Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-36742US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.