First published: Sat Jan 08 2022(Updated: )
A link following denial-of-service vulnerability in Trend Micro Worry-Free Business Security (on prem only) could allow a local attacker to overwrite arbitrary files in the context of SYSTEM. This is similar to, but not the same as CVE-2021-44024. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro Worry-Free Business Security | ||
Trendmicro Apex One | =2019 | |
Trendmicro Apex One | =2019 | |
Trendmicro Worry-free Business Security | =10.0-sp1 | |
Trendmicro Worry-free Business Security Services | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-45442.
The severity of CVE-2021-45442 is high with a CVSS score of 7.1.
The affected software for CVE-2021-45442 is Trend Micro Apex One and Worry-Free Business Security (version 2019) and Trendmicro Worry-free Business Security (version 10.0-sp1).
An attacker can exploit CVE-2021-45442 by executing low-privileged code on the target system.
You can find more information about CVE-2021-45442 at the following references: [Link 1](https://success.trendmicro.com/solution/000289996), [Link 2](https://www.zerodayinitiative.com/advisories/ZDI-22-015/).