Trend Micro Multiple Products Improper Input Validation Vulnerability
Trend Micro — Apex One, Apex One as a Service, and Worry-Free Business Security
- Added to KEV catalog
- 3 November 2021
- Federal remediation due date
- 17 November 2021
- Weakness classification (CWE)
- CWE-20
CISA Description
Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows for privilege escalation.
Required action
Apply updates per vendor instructions.
Notes
https://success.trendmicro.com/dcx/s/solution/000287819?language=en_US, https://success.trendmicro.com/dcx/s/solution/000287820?language=en_US; https://nvd.nist.gov/vuln/detail/CVE-2021-36742
More Trend Micro Vulnerabilities
Trend Micro Apex One (On-Premise) Directory Traversal Vulnerability
Trend Micro Apex One OS Command Injection Vulnerability
Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability
Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability
Trend Micro Apex Central Arbitrary File Upload Vulnerability
Is this vulnerability present in your environment?
CRS delivers independent VAPT assessments that identify exactly which known-exploited vulnerabilities exist in your network, applications, and infrastructure.
Explore VAPT Services