CVE-2021-44024: Trend Micro Apex One Link Following Denial-of-Service Vulnerability
A link following denial-of-service vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to overwrite arbitrary files in the context of SYSTEM. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Other sources
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Trend Micro Apex One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Real-time Scan Service. By creating a symbolic link, an attacker can abuse the service to overwrite a file. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-44024?
CVE-2021-44024 is a vulnerability that allows local attackers to create a denial-of-service condition on affected installations of Trend Micro Apex One Security Agent.
What is the severity level of CVE-2021-44024?
The severity level of CVE-2021-44024 is high, with a score of 7.1.
How does CVE-2021-44024 affect Trend Micro Apex One?
CVE-2021-44024 affects Trend Micro Apex One version 2019 and Worry-Free Business Security version 10.0-sp1.
How can CVE-2021-44024 be exploited?
An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit CVE-2021-44024.
Where can I find more information about CVE-2021-44024?
You can find more information about CVE-2021-44024 at the following references: [Trend Micro Solution ID 000289996](https://success.trendmicro.com/solution/000289996) and [Zero Day Initiative Advisory ZDI-22-014](https://www.zerodayinitiative.com/advisories/ZDI-22-014/).