PT-2021-3451 · Trend Micro · Trend Micro Housecall For Home Networks
Xavier Danest
·
Published
2021-04-22
·
Updated
2021-05-21
·
CVE-2021-31519
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Trend Micro HouseCall for Home Networks versions 5.3.1179 and below
Description
The issue is related to an incorrect permission vulnerability in the product installer folders, which could allow an attacker to escalate privileges by placing arbitrary code on a specified folder and having that code executed by an Administrator who is running a scan. An attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.
Recommendations
For versions 5.3.1179 and below, consider restricting access to the product installer folders to minimize the risk of exploitation until a patch is available.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Incorrect Default Permissions
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trend Micro Housecall For Home Networks