PT-2021-3450 · Trend Micro · Trend Micro Housecall For Home Networks

Xavier Danest

·

Published

2021-04-22

·

Updated

2021-05-21

·

CVE-2021-28649

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Trend Micro HouseCall for Home Networks versions 5.3.1179 and below
Description The issue is related to incorrect permission assignment, which could allow an attacker to escalate privileges. This can be achieved by placing arbitrary code in a specified folder, and having that code executed by an Administrator running a scan. The attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
Recommendations For versions 5.3.1179 and below, update to a version above 5.3.1179 to resolve the issue. As a temporary workaround, consider restricting access to the specified folder where arbitrary code can be placed to minimize the risk of exploitation.

Fix

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03310
CVE-2021-28649
ZDI-21-474

Affected Products

Trend Micro Housecall For Home Networks