First published: Sat Jan 08 2022(Updated: )
A origin validation error vulnerability in Trend Micro Apex One (on-prem and SaaS) could allow a local attacker drop and manipulate a specially crafted file to issue commands over a certain pipe and elevate to a higher level of privileges. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Credit: security@trendmicro.com security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trendmicro Apex One | =2019 | |
Trendmicro Apex One | =2019 | |
Trendmicro Worry-free Business Security | =10.0-sp1 | |
Trendmicro Worry-free Business Security Services | ||
Microsoft Windows | ||
Trend Micro Apex One | ||
All of | ||
Any of | ||
Trendmicro Apex One | =2019 | |
Trendmicro Apex One | =2019 | |
Trendmicro Worry-free Business Security | =10.0-sp1 | |
Trendmicro Worry-free Business Security Services | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-45441 is a vulnerability that allows local attackers to escalate privileges on affected installations of Trend Micro Apex One Security Agent.
In order to exploit this vulnerability, an attacker must first obtain the ability to execute low-privileged code on the target system.
CVE-2021-45441 has a severity score of 7.8 (high).
Affected software versions include Trend Micro Apex One 2019, Trend Micro Worry-Free Business Security 10.0 SP1, and Trend Micro Worry-Free Business Security Services.
To fix CVE-2021-45441, it is recommended to update to the latest version of Trend Micro Apex One Security Agent or apply the necessary patches provided by the vendor.