Trend Micro · Officescan Xg Sp1 · CVE-2021-25253
**Name of the Vulnerable Software and Affected Versions**
Trend Micro Apex One versions (affected versions not specified)
Trend Micro Apex One as a Service versions (affected versions not specified)
OfficeScan XG SP1 versions (affected versions not specified)
**Description**
The issue is related to improper access control in the mentioned software, which could allow a local attacker to escalate privileges on affected installations. To exploit this, an attacker must first obtain the ability to execute low-privileged code on the target system.
**Recommendations**
For Trend Micro Apex One, consider restricting access to the service until a patch is available.
For Trend Micro Apex One as a Service, restrict access to the service until a patch is available.
For OfficeScan XG SP1, restrict access to the resource used by the service until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.