First published: Wed Oct 06 2021(Updated: )
An arbitrary file creation by privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1, and Worry-Free Business Security Services could allow a local attacker to create an arbitrary file with higher privileges that could lead to a denial-of-service (DoS) on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trendmicro Apex One | =2019 | |
Trendmicro Worry-free Business Security | =10.0-sp1 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-3848 is an arbitrary file creation by privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1, and Worry-Free Business Security Services.
CVE-2021-3848 allows a local attacker to create an arbitrary file with higher privileges, leading to a denial of service.
CVE-2021-3848 has a severity rating of medium (5.5).
To fix CVE-2021-3848, apply the necessary security updates provided by Trend Micro or apply patches and updates as recommended.
You can find more information about CVE-2021-3848 in the reference provided by Trend Micro: https://success.trendmicro.com/solution/000289183