PT-2021-22154 · Trend Micro · Trend Micro Worry-Free Business Security Services+3
Published
2021-10-06
·
Updated
2022-07-12
·
CVE-2021-3848
CVSS v3.1
5.5
Medium
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Trend Micro Apex One version 10.0 SP1
Trend Micro Apex One as a Service version 10.0 SP1
Trend Micro Worry-Free Business Security version 10.0 SP1
Trend Micro Worry-Free Business Security Services version 10.0 SP1
Description
An arbitrary file creation by privilege escalation issue could allow a local attacker to create an arbitrary file with higher privileges, potentially leading to a denial-of-service (DoS) on affected installations. The attacker must first obtain the ability to execute low-privileged code on the target system to exploit this issue.
Recommendations
For Trend Micro Apex One version 10.0 SP1, update to a version that includes a fix for this issue.
For Trend Micro Apex One as a Service version 10.0 SP1, update to a version that includes a fix for this issue.
For Trend Micro Worry-Free Business Security version 10.0 SP1, update to a version that includes a fix for this issue.
For Trend Micro Worry-Free Business Security Services version 10.0 SP1, update to a version that includes a fix for this issue.
As a temporary workaround, consider restricting access to sensitive areas of the system to minimize the risk of exploitation.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trend Micro Apex One
Trend Micro Apex One As A Service
Trend Micro Worry-Free Business Security
Trend Micro Worry-Free Business Security Services