PT-2021-3451 · Trend Micro · Trend Micro Housecall For Home Networks

Xavier Danest

·

Published

2021-04-22

·

Updated

2021-05-21

·

CVE-2021-31519

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Trend Micro HouseCall for Home Networks versions 5.3.1179 and below
Description The issue is related to an incorrect permission vulnerability in the product installer folders, which could allow an attacker to escalate privileges by placing arbitrary code on a specified folder and having that code executed by an Administrator who is running a scan. An attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
Recommendations For versions 5.3.1179 and below, consider restricting access to the product installer folders to minimize the risk of exploitation until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03311
CVE-2021-31519
ZDI-21-475

Affected Products

Trend Micro Housecall For Home Networks