HIGH KEV
A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations
Published Jul 29, 2021 ·Due Nov 17, 2021
7.8
HIGHCVSS 3.1
EPSS 1.48%
Description
A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Affected products
-
- Version 2019, SaaSStatusaffectedConstraints-
- Version
-
- Version XG SP1StatusaffectedConstraints-
- Version
-
- Version 10.0 SP1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Trend Micro | Trend Micro Apex One | n/a |
| ||||||
| Trend Micro | Trend Micro OfficeScan | n/a |
| ||||||
| Trend Micro | Trend Micro Worry-Free Business Security | n/a |
|
Configuration 1
OR
- xg
- 10.0
Configuration 2
AND
OR
- 2019
- 10.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (6)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-23332 Advisory
- https://success.trendmicro.com/jp/solution/000287796 x_refsource_MISCVendor Advisory
- https://success.trendmicro.com/jp/solution/000287815 x_refsource_MISCVendor Advisory
- https://success.trendmicro.com/solution/000287819 x_refsource_MISCVendor Advisory
- https://success.trendmicro.com/solution/000287820 x_refsource_MISCVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-36742 government-resourceUS Government Resource
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2021-23332 | Advisory | |
| https://success.trendmicro.com/jp/solution/000287796 | x_refsource_MISCVendor Advisory | |
| https://success.trendmicro.com/jp/solution/000287815 | x_refsource_MISCVendor Advisory | |
| https://success.trendmicro.com/solution/000287819 | x_refsource_MISCVendor Advisory | |
| https://success.trendmicro.com/solution/000287820 | x_refsource_MISCVendor Advisory | |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-36742 | government-resourceUS Government Resource |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner trendmicro
Published Jul 29, 2021
Updated Oct 21, 2025
Reserved Jul 14, 2021
Link CVE-2021-36742
CISA Vulnrichment
Updated Feb 6, 2025
ENISA EUVD
EUVD-2021-23332 Assigner trendmicro
Published Jul 29, 2021
Updated Oct 21, 2025
Exploited since Nov 3, 2021
Link EUVD-2021-23332