PT-2021-16478 · Trend Micro · Trend Micro Worry-Free Business Security 10.0 Sp1+2
Elias Martinez
+1
·
Published
2021-01-29
·
Updated
2021-02-05
·
CVE-2021-25240
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
Trend Micro Apex One versions (affected versions not specified)
Trend Micro OfficeScan XG SP1
Trend Micro Worry-Free Business Security 10.0 SP1
Description:
An improper access control issue could allow an unauthenticated user to obtain x64 agent hofitx information.
Recommendations:
For Trend Micro Apex One, update to a version that addresses the improper access control issue.
For Trend Micro OfficeScan XG SP1, consider applying configuration changes to restrict access until a patch is available.
For Trend Micro Worry-Free Business Security 10.0 SP1, restrict access to sensitive information to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trend Micro Apex One
Trend Micro Officescan Xg Sp1
Trend Micro Worry-Free Business Security 10.0 Sp1