CVE-2021-25251: Code Injection
The Trend Micro Security 2020 and 2021 families of consumer products are vulnerable to a code injection vulnerability which could allow an attacker to disable the program's password protection and disable protection. An attacker must already have administrator privileges on the machine to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-25251?
CVE-2021-25251 is a code injection vulnerability in Trend Micro Security 2020 and 2021 families of consumer products.
How can an attacker exploit CVE-2021-25251?
To exploit CVE-2021-25251, an attacker must already have administrator privileges on the machine and can disable the program's password protection and disable protection.
Which Trend Micro products are affected by CVE-2021-25251?
Trendmicro Antivirus+ Security 2020, Trendmicro Antivirus+ Security 2021, Trendmicro Internet Security 2020, Trendmicro Internet Security 2021, Trendmicro Maximum Security 2020, Trend Micro Maximum Security, Trendmicro Premium Security 2020, and Trendmicro Premium Security 2021 are affected by CVE-2021-25251.
What is the severity of CVE-2021-25251?
The severity of CVE-2021-25251 is high with a CVSS score of 7.2.
How can I fix CVE-2021-25251?
To fix CVE-2021-25251, update your Trend Micro Security product to the latest version available.