CVE-2021-45440: Trend Micro Worry-Free Business Security Unnecessary Privileges Local Privilege Escalation Vulnerability
A unnecessary privilege vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security 10.0 SP1 (on-prem versions only) could allow a local attacker to abuse an impersonation privilege and elevate to a higher level of privileges. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro Worry-Free Business Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Security Server. The issue results from allowing an untrusted process to impersonate the client of a pipe. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2021-45440?
CVE-2021-45440 is a vulnerability that allows local attackers to escalate privileges on affected installations of Trend Micro Worry-Free Business Security.
How does CVE-2021-45440 affect Trend Micro Worry-Free Business Security?
CVE-2021-45440 affects Trend Micro Worry-Free Business Security by allowing local attackers to escalate privileges.
What is the severity of CVE-2021-45440?
CVE-2021-45440 has a severity rating of 7.8 (high).
How can CVE-2021-45440 be exploited?
CVE-2021-45440 can be exploited by local attackers who have the ability to execute low-privileged code on the target system.
How can I fix the CVE-2021-45440 vulnerability?
To fix the CVE-2021-45440 vulnerability, update Trend Micro Worry-Free Business Security to the latest version available.