CVE-2021-42011: Trend Micro Apex One Incorrect Permission Assignment Privilege Escalation Vulnerability
An incorrect permission assignment vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to load a DLL with escalated privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro Apex One. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the ApexOne Security Agent. The issue results from incorrect permissions set on a resource used by the service. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the severity of CVE-2021-42011?
CVE-2021-42011 is classified as a high-severity vulnerability due to its potential for privilege escalation.
How do I fix CVE-2021-42011?
To fix CVE-2021-42011, you should apply the latest security updates provided by Trend Micro for Apex One.
Who is affected by CVE-2021-42011?
CVE-2021-42011 affects installations of Trend Micro Apex One version 2019.
What is the nature of CVE-2021-42011?
CVE-2021-42011 is a vulnerability related to incorrect permission assignments that can allow local attackers to load a DLL with elevated privileges.
Can CVE-2021-42011 be exploited remotely?
No, CVE-2021-42011 requires local access to the affected system to exploit the vulnerability.