PT-2021-3842 · Trend Micro · Trend Micro Worry-Free Business Security+3
Published
2021-07-28
·
Updated
2025-10-31
·
CVE-2021-36741
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Trend Micro Apex One versions prior to the fixed version
Trend Micro Apex One as a Service versions prior to the fixed version
Trend Micro OfficeScan XG versions prior to the fixed version
Trend Micro Worry-Free Business Security 10.0 SP1 and earlier
Description
An improper input validation vulnerability in Trend Micro products allows a remote attacker to upload arbitrary files on affected installations. The attacker must first obtain the ability to logon to the product's management console in order to exploit this vulnerability. This vulnerability may allow a remote attacker to impact the confidentiality, integrity, and availability of protected information by uploading a specially crafted file.
Recommendations
For Trend Micro Apex One, update to a version that includes the fix for this vulnerability.
For Trend Micro Apex One as a Service, update to a version that includes the fix for this vulnerability.
For Trend Micro OfficeScan XG, update to a version that includes the fix for this vulnerability.
For Trend Micro Worry-Free Business Security, update to a version later than 10.0 SP1.
As a temporary workaround, consider restricting access to the management console to minimize the risk of exploitation.
Fix
Unrestricted File Upload
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Trend Micro Apex One
Trend Micro Apex One As A Service
Trend Micro Officescan Xg
Trend Micro Worry-Free Business Security