First published: Sat Jan 08 2022(Updated: )
A link following denial-of-service vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to overwrite arbitrary files in the context of SYSTEM. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Credit: security@trendmicro.com security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trendmicro Apex One | =2019 | |
Trendmicro Apex One | =2019 | |
Trendmicro Worry-free Business Security | =10.0-sp1 | |
Trendmicro Worry-free Business Security Services | ||
Microsoft Windows | ||
Trend Micro Apex One | ||
All of | ||
Any of | ||
Trendmicro Apex One | =2019 | |
Trendmicro Apex One | =2019 | |
Trendmicro Worry-free Business Security | =10.0-sp1 | |
Trendmicro Worry-free Business Security Services | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-44024 is a vulnerability that allows local attackers to create a denial-of-service condition on affected installations of Trend Micro Apex One Security Agent.
The severity level of CVE-2021-44024 is high, with a score of 7.1.
CVE-2021-44024 affects Trend Micro Apex One version 2019 and Worry-Free Business Security version 10.0-sp1.
An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit CVE-2021-44024.
You can find more information about CVE-2021-44024 at the following references: [Trend Micro Solution ID 000289996](https://success.trendmicro.com/solution/000289996) and [Zero Day Initiative Advisory ZDI-22-014](https://www.zerodayinitiative.com/advisories/ZDI-22-014/).