CVE-2021-45442: Trend Micro Worry-Free Business Security Link Following Denial-of-Service Vulnerability
A link following denial-of-service vulnerability in Trend Micro Worry-Free Business Security (on prem only) could allow a local attacker to overwrite arbitrary files in the context of SYSTEM. This is similar to, but not the same as CVE-2021-44024. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Other sources
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Trend Micro Worry-Free Business Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Trend Micro Security Agent Listener service. By creating a symbolic link, an attacker can abuse the service to overwrite a file. An attacker can leverage this vulnerability to create a denial-of-service condition on the system.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-45442.
What is the severity of CVE-2021-45442?
The severity of CVE-2021-45442 is high with a CVSS score of 7.1.
What is the affected software for CVE-2021-45442?
The affected software for CVE-2021-45442 is Trend Micro Apex One and Worry-Free Business Security (version 2019) and Trendmicro Worry-free Business Security (version 10.0-sp1).
How can an attacker exploit CVE-2021-45442?
An attacker can exploit CVE-2021-45442 by executing low-privileged code on the target system.
Where can I find more information about CVE-2021-45442?
You can find more information about CVE-2021-45442 at the following references: [Link 1](https://success.trendmicro.com/solution/000289996), [Link 2](https://www.zerodayinitiative.com/advisories/ZDI-22-015/).