PT-2021-3450 · Trend Micro · Trend Micro Housecall For Home Networks
Xavier Danest
·
Published
2021-04-22
·
Updated
2021-05-21
·
CVE-2021-28649
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Trend Micro HouseCall for Home Networks versions 5.3.1179 and below
Description
The issue is related to incorrect permission assignment, which could allow an attacker to escalate privileges. This can be achieved by placing arbitrary code in a specified folder, and having that code executed by an Administrator running a scan. The attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
Recommendations
For versions 5.3.1179 and below, update to a version above 5.3.1179 to resolve the issue.
As a temporary workaround, consider restricting access to the specified folder where arbitrary code can be placed to minimize the risk of exploitation.
Fix
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trend Micro Housecall For Home Networks