PT-2021-22154 · Trend Micro · Trend Micro Worry-Free Business Security Services+3

Published

2021-10-06

·

Updated

2022-07-12

·

CVE-2021-3848

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Trend Micro Apex One version 10.0 SP1 Trend Micro Apex One as a Service version 10.0 SP1 Trend Micro Worry-Free Business Security version 10.0 SP1 Trend Micro Worry-Free Business Security Services version 10.0 SP1
Description An arbitrary file creation by privilege escalation issue could allow a local attacker to create an arbitrary file with higher privileges, potentially leading to a denial-of-service (DoS) on affected installations. The attacker must first obtain the ability to execute low-privileged code on the target system to exploit this issue.
Recommendations For Trend Micro Apex One version 10.0 SP1, update to a version that includes a fix for this issue. For Trend Micro Apex One as a Service version 10.0 SP1, update to a version that includes a fix for this issue. For Trend Micro Worry-Free Business Security version 10.0 SP1, update to a version that includes a fix for this issue. For Trend Micro Worry-Free Business Security Services version 10.0 SP1, update to a version that includes a fix for this issue. As a temporary workaround, consider restricting access to sensitive areas of the system to minimize the risk of exploitation.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2021-3848

Affected Products

Trend Micro Apex One
Trend Micro Apex One As A Service
Trend Micro Worry-Free Business Security
Trend Micro Worry-Free Business Security Services