CVE-2021-32465: Trend Micro Apex One Incorrect Permission Preservation Authentication Bypass Vulnerability
An incorrect permission preservation vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a remote user to perform an attack and bypass authentication on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Other sources
This vulnerability allows remote attackers to bypass authentication on affected installations of Trend Micro Apex One. Authentication as a low-privileged Windows domain user is required to exploit this vulnerability. The specific flaw exists within the product patching functionality. When applying a patch to the product, the permissions on some files are not properly preserved. An attacker can leverage this vulnerability to bypass authentication on the system.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-32465?
CVE-2021-32465 is a vulnerability in Trend Micro Apex One that allows remote attackers to bypass authentication.
What is the severity of CVE-2021-32465?
The severity of CVE-2021-32465 is high with a severity score of 8.8.
How does CVE-2021-32465 affect Trend Micro Apex One?
CVE-2021-32465 affects Trend Micro Apex One by allowing remote attackers to bypass authentication.
How can this vulnerability be exploited?
This vulnerability can be exploited by remote attackers who have low-privileged Windows domain user authentication.
What is the recommended solution for CVE-2021-32465?
It is recommended to apply the patch provided by Trend Micro to fix CVE-2021-32465.