Vulnerabilidades em Trend Micro

315 resultados
Análise Vexday

Com 9 CVEs confirmadas em exploração ativa no catálogo CISA KEV, a Trend Micro apresenta uma taxa de exploração 6,4 vezes acima da média geral do catálogo, o que indica que vulnerabilidades nessa tecnologia têm historicamente atraído atenção real de agentes maliciosos, não apenas teórica. Das 315 CVEs catalogadas, 28 possuem prova de conceito pública, ampliando a superfície de risco para equipes que operam versões desatualizadas. O maior EPSS observado chega a 0,8966, sinalizando que ao menos uma vulnerabilidade tem altíssima probabilidade estimada de exploração. A CVE mais perigosa em atividade apontada pelos dados é a CVE-2019-18187, com EPSS de 0,2513, sendo classificada como CWE-125 (leitura fora dos limites) o tipo de falha mais recorrente no portfólio, o que sugere atenção especial a controles de integridade de memória na priorização de correções.

CVE-2021-25237An improper access control vulnerability in Trend Micro Apex One (on-prem) could allow an unauthenticated user to obtain information about tEPSS 1.6%CVE-2018-6218A DLL Hijacking vulnerability in Trend Micro's User-Mode Hooking Module (UMH) could allow an attacker to run arbitrary code on a vulnerable EPSS 1.6%CVE-2019-14687A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrarEPSS 1.6%CVE-2021-25244An improper access control vulnerability in Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain various piecEPSS 1.5%CVE-2021-25245An improper access control vulnerability in Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain various piecEPSS 1.5%CVE-2021-36742HIGHA improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.EPSS 1.5%KEVCVE-2019-14684A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrarEPSS 1.5%CVE-2019-19690Trend Micro Mobile Security for Android (Consumer) versions 10.3.1 and below on Android 8.0+ has an issue in which an attacker could bypass EPSS 1.5%CVE-2019-9490A vulnerability in Trend Micro InterScan Web Security Virtual Appliance version 6.5 SP2 could allow an non-authorized user to disclose adminEPSS 1.5%CVE-2021-31521Trend Micro InterScan Web Security Virtual Appliance version 6.5 was found to have a reflected cross-site scripting (XSS) vulnerability in tEPSS 1.4%CVE-2018-18331A Trend Micro OfficeScan XG weak file permissions vulnerability on a particular folder for a particular group may allow an attacker to alterEPSS 1.4%CVE-2018-18332A Trend Micro OfficeScan XG weak file permissions vulnerability may allow an attacker to potentially manipulate permissions on some key fileEPSS 1.4%CVE-2018-10507A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to take a series of steps to bypass or render the OfficeScaEPSS 1.4%CVE-2018-10508A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to use a specially crafted URL to elevate account permissioEPSS 1.3%CVE-2020-25772An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive informEPSS 1.3%CVE-2020-24564An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive informEPSS 1.3%CVE-2020-24565An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive informEPSS 1.3%CVE-2020-25770An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive informEPSS 1.3%CVE-2020-25771An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive informEPSS 1.3%CVE-2020-25777Trend Micro Antivirus for Mac 2020 (Consumer) is vulnerable to a specific kernel extension request attack where an attacker could bypass theEPSS 1.3%