Trend Micro · Trend Micro Apex One · CVE-2021-25248
Name of the Vulnerable Software and Affected Versions:
Trend Micro Apex One (on-prem and SaaS)
OfficeScan XG SP1
Worry-Free Business Security versions 10.0 SP1 and Services
Description:
An out-of-bounds read information disclosure issue could allow an attacker to disclose sensitive information about a named pipe. The attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this issue.
Recommendations:
For Trend Micro Apex One (on-prem and SaaS), update to a version that includes a fix for this issue.
For OfficeScan XG SP1, update to a version that includes a fix for this issue.
For Worry-Free Business Security versions 10.0 SP1 and Services, update to a version that includes a fix for this issue.
As a temporary workaround, consider restricting access to named pipes to minimize the risk of exploitation.