PT-2021-16465 · Trend Micro · Trend Micro Antivirus For Mac 2021

Michael Deplante

·

Published

2021-01-29

·

Updated

2021-02-08

·

CVE-2021-25227

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions: Trend Micro Antivirus for Mac 2021 (Consumer)
Description: The issue is a memory exhaustion vulnerability that could lead to disabling all the scanning functionality within the application. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability, meaning the attacker must already have access to the target system, either legitimately or via another exploit.
Recommendations: For Trend Micro Antivirus for Mac 2021 (Consumer), consider restricting access to the application until a patch is available, as a temporary workaround to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Resource Exhaustion

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-25227
ZDI-21-102

Affected Products

Trend Micro Antivirus For Mac 2021