Vulnerabilities > Trendmicro > Apex ONE > High

DATE CVE VULNERABILITY TITLE RISK
2021-07-29 CVE-2021-36741 Unrestricted Upload of File with Dangerous Type vulnerability in Trendmicro products
An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations.
network
low complexity
trendmicro CWE-434
8.8
2021-07-29 CVE-2021-36742 Improper Input Validation vulnerability in Trendmicro products
A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations.
local
low complexity
trendmicro CWE-20
7.8
2021-07-20 CVE-2021-32463 Incorrect Permission Assignment for Critical Resource vulnerability in Trendmicro Apex ONE and Worry-Free Business Security
An incorrect permission assignment denial-of-service vulnerability in Trend Micro Apex One, Apex One as a Service (SaaS), Worry-Free Business Security 10.0 SP1 and Worry-Free Servgices could allow a local attacker to escalate privileges and delete files with system privileges on affected installations.
local
low complexity
trendmicro CWE-732
7.8
2021-04-13 CVE-2021-28645 Incorrect Permission Assignment for Critical Resource vulnerability in Trendmicro Apex ONE and Officescan
An incorrect permission assignment vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a local attacker to escalate privileges on affected installations.
local
low complexity
trendmicro CWE-732
7.8
2021-04-13 CVE-2021-25253 Incorrect Permission Assignment for Critical Resource vulnerability in Trendmicro Apex ONE and Officescan
An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a resource used by the service could allow a local attacker to escalate privileges on affected installations.
local
low complexity
trendmicro CWE-732
7.8
2021-04-13 CVE-2021-25250 Incorrect Permission Assignment for Critical Resource vulnerability in Trendmicro Apex ONE and Officescan
An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a sensitive file could allow a local attacker to escalate privileges on affected installations.
local
low complexity
trendmicro CWE-732
7.8
2021-02-04 CVE-2021-25249 Out-of-bounds Write vulnerability in Trendmicro Apex One, Officescan and Worry-Free Business Security
An out-of-bounds write information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to escalate privileges on affected installations.
local
low complexity
trendmicro CWE-787
7.8
2020-11-18 CVE-2020-28572 Unspecified vulnerability in Trendmicro Apex ONE 2019
A vulnerability in Trend Micro Apex One could allow an unprivileged user to abuse the product installer to reinstall the agent with additional malicious code in the context of a higher privilege.
local
low complexity
trendmicro
7.8
2020-09-29 CVE-2020-25773 Double Free vulnerability in Trendmicro Apex ONE 2019/Saas
A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to execute arbitrary code on affected products.
local
low complexity
trendmicro CWE-415
7.8
2020-09-29 CVE-2020-24563 Improper Authentication vulnerability in Trendmicro Apex ONE 2019/Saas
A vulnerability in Trend Micro Apex One may allow a local attacker to manipulate the process of the security agent unload option (if configured), which then could be manipulated to gain a privilege escalation and code execution.
local
low complexity
trendmicro CWE-287
7.8