Vulnerabilities > CVE-2021-25249 - Out-of-bounds Write vulnerability in Trendmicro Apex One, Officescan and Worry-Free Business Security
Attack vector
LOCAL Attack complexity
LOW Privileges required
LOW Confidentiality impact
HIGH Integrity impact
HIGH Availability impact
HIGH Summary
An out-of-bounds write information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 3 | |
OS | 1 |
Common Weakness Enumeration (CWE)
References
- https://success.trendmicro.com/solution/000284202
- https://success.trendmicro.com/solution/000284202
- https://success.trendmicro.com/solution/000284205
- https://success.trendmicro.com/solution/000284205
- https://success.trendmicro.com/solution/000284206
- https://success.trendmicro.com/solution/000284206
- https://www.zerodayinitiative.com/advisories/ZDI-21-119/
- https://www.zerodayinitiative.com/advisories/ZDI-21-119/