Vulnerabilidades em Trend Micro

315 resultados
Análise Vexday

Com 9 CVEs confirmadas em exploração ativa no catálogo CISA KEV, a Trend Micro apresenta uma taxa de exploração 6,4 vezes acima da média geral do catálogo, o que indica que vulnerabilidades nessa tecnologia têm historicamente atraído atenção real de agentes maliciosos, não apenas teórica. Das 315 CVEs catalogadas, 28 possuem prova de conceito pública, ampliando a superfície de risco para equipes que operam versões desatualizadas. O maior EPSS observado chega a 0,8966, sinalizando que ao menos uma vulnerabilidade tem altíssima probabilidade estimada de exploração. A CVE mais perigosa em atividade apontada pelos dados é a CVE-2019-18187, com EPSS de 0,2513, sendo classificada como CWE-125 (leitura fora dos limites) o tipo de falha mais recorrente no portfólio, o que sugere atenção especial a controles de integridade de memória na priorização de correções.

CVE-2018-6235An Out-of-Bounds write privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to esEPSS 0.5%CVE-2021-36744Trend Micro Security (Consumer) 2021 and 2020 are vulnerable to a directory junction vulnerability which could allow an attacker to exploit EPSS 0.5%CVE-2018-15363An Out-of-Bounds Read Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to esEPSS 0.5%CVE-2021-28647Trend Micro Password Manager version 5 (Consumer) is vulnerable to a DLL Hijacking vulnerability which could allow an attacker to inject a mEPSS 0.5%CVE-2021-45440A unnecessary privilege vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security 10.0 SP1 (on-prem versions only) EPSS 0.5%CVE-2021-42103An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalaEPSS 0.5%CVE-2021-42102An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service agents could allow a local attacker toEPSS 0.5%CVE-2021-42101An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalaEPSS 0.5%CVE-2020-8469Trend Micro Password Manager for Windows version 5.0 is affected by a DLL hijacking vulnerability would could potentially allow an attacker EPSS 0.5%CVE-2020-27013Trend Micro Antivirus for Mac 2020 (Consumer) contains a vulnerability in the product that occurs when a webserver is started that implementEPSS 0.4%CVE-2021-32457Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vulnerability which coulEPSS 0.4%CVE-2020-28572A vulnerability in Trend Micro Apex One could allow an unprivileged user to abuse the product installer to reinstall the agent with additionEPSS 0.4%CVE-2021-25249An out-of-bounds write information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free BuEPSS 0.4%CVE-2021-28646An insecure file permissions vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a local attackerEPSS 0.4%CVE-2022-24671A link following privilege escalation vulnerability in Trend Micro Antivirus for Max 11.0.2150 and below could allow a local attacker to modEPSS 0.4%CVE-2022-40709An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local EPSS 0.4%CVE-2021-42108Unnecessary privilege vulnerabilities in the Web Console of Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security 10.EPSS 0.4%CVE-2018-10514A Missing Impersonation Privilege Escalation vulnerability in Trend Micro Security 2018 (Consumer) products could allow a local attacker to EPSS 0.4%CVE-2021-44023A link following denial-of-service (DoS) vulnerability in the Trend Micro Security (Consumer) 2021 familiy of products could allow an attackEPSS 0.4%CVE-2021-25226A memory exhaustion vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow a local attacker to craft specific files that can cEPSS 0.4%