CVE-2021-36741
CVE-2021-36741
In short
A flaw in Trend Micro security products allows someone with console access to upload any file they want, bypassing safety checks. This is dangerous because it can lead to installing malicious code on protected systems.
Technical detail
Improper input validation in file upload functionality allows authenticated users with management console access to bypass file type restrictions and upload arbitrary files. This can facilitate remote code execution or system compromise on affected Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 installations.
Summary generated and translated by AI from the official description.
An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the ability to logon to the product�s management console in order to exploit this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Affected products
Trend Micro · Trend Micro Apex OneTrend Micro · Trend Micro OfficeScanTrend Micro · Trend Micro Worry-Free Business SecurityWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →