CVE-2021-36741: Trend Micro Multiple Products Improper Input Validation Vulnerability
An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the ability to logon to the product?s management console in order to exploit this vulnerability.
Other sources
An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the ability to logon to the product�s management console in order to exploit this vulnerability.
— MITRE
Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows a remote attacker to upload files.
— CISA
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-36741?
CVE-2021-36741 is an improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security.
How does CVE-2021-36741 affect Trend Micro products?
CVE-2021-36741 allows a remote attacker to upload arbitrary files on affected installations of Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security.
What is the severity of CVE-2021-36741?
CVE-2021-36741 has a severity score of 8.8 (high severity).
How can I fix CVE-2021-36741?
To fix CVE-2021-36741, users should apply the necessary patches or updates provided by Trend Micro.
Where can I find more information about CVE-2021-36741?
You can find more information about CVE-2021-36741 on the Trend Micro website. (References: [1](https://success.trendmicro.com/dcx/s/solution/000287819?language=en_US), [2](https://success.trendmicro.com/dcx/s/solution/000287820?language=en_US), [3](https://success.trendmicro.com/jp/solution/000287796))