First published: Tue Apr 13 2021(Updated: )
An incorrect permission assignment vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro Apex One | ||
Trendmicro Apex One | =2019 | |
Trendmicro Apex One | =2019 | |
Trendmicro Officescan | =xg-sp1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-28645.
The severity of CVE-2021-28645 is high (7.8).
This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro Apex One by exploiting an incorrect permission assignment.
An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Yes, Trend Micro has released a fix for this vulnerability. Please refer to the vendor's advisory for the appropriate patch or update.