Trend Micro Vulnerabilities and Affected Products
Vulnerabilities associated with Trend Micro OfficeScan.
Products
Clear product- Trend Micro Apex One81 vulnerabilities
- Trend Micro OfficeScan53 vulnerabilities
- Trend Micro Worry-Free Business Security46 vulnerabilities
- Trend Micro Security (Consumer)27 vulnerabilities
- Trend Micro Email Encryption Gateway18 vulnerabilities
- Trend Micro InterScan Web Security Virtual Appliance16 vulnerabilities
- Trend Micro Antivirus for Mac (Consumer)12 vulnerabilities
- Trend Micro Control Manager11 vulnerabilities
- Trend Micro Password Manager10 vulnerabilities
- Trend Micro Deep Security8 vulnerabilities
- Trend Micro Smart Protection Server (Standalone)8 vulnerabilities
- Trend Micro HouseCall for Home Networks6 vulnerabilities
- Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA)6 vulnerabilities
- Trend Micro Maximum Security6 vulnerabilities
- Trend Micro Antivirus for Mac5 vulnerabilities
- Trend Micro Home Network Security5 vulnerabilities
- Trend Micro ServerProtect for Linux5 vulnerabilities
- Trend Micro ServerProtect for EMC Celerra4 vulnerabilities
- Trend Micro ServerProtect for Microsoft Windows / Novell NetWare4 vulnerabilities
- Trend Micro ServerProtect for Network Appliance Filers4 vulnerabilities
- Trend Micro ServerProtect for Storage4 vulnerabilities
- Apex One and Apex One as a Service3 vulnerabilities
- Mobile Security (Enterprise)3 vulnerabilities
- Trend Micro Anti-Threat Toolkit (ATTK)3 vulnerabilities
- Trend Micro InterScan Messaging Security Virtual Appliance3 vulnerabilities
| Vulnerability | Title and context | CVSS | EPSS | PoCs | Signals | STIX action |
|---|---|---|---|---|---|---|
CVE-2021-32465HIGH | An incorrect permission preservation vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a remote user to perform an attack and bypass authentication on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. CWE-281Aug 4, 2021 | CVSS8.8v3.1 | EPSS4.34% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-36742HIGH | Trend Micro Multiple Products Improper Input Validation VulnerabilityA improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. CWE-20Jul 29, 2021 | CVSS7.8v3.1 | EPSS1.48% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-36741HIGH | Trend Micro Multiple Products Improper Input Validation VulnerabilityAn improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the ability to logon to the product�s management console in order to exploit this vulnerability. | CVSS8.8v3.1 | EPSS4.95% | PoCs0 | SignalsListed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28646MEDIUM | An insecure file permissions vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a local attacker to take control of a specific log file on affected installations. CWE-732Apr 13, 2021 | CVSS5.5v3.1 | EPSS0.424% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-28645HIGH | An incorrect permission assignment vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. CWE-732Apr 13, 2021 | CVSS7.8v3.1 | EPSS0.508% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25253HIGH | An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a resource used by the service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | CVSS7.8v3.1 | EPSS1.91% | PoCs1 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25250HIGH | An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a sensitive file could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | CVSS7.8v3.1 | EPSS0.508% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25249HIGH | An out-of-bounds write information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. CWE-787Feb 4, 2021 | CVSS7.8v3.1 | EPSS0.426% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25248MEDIUM | An out-of-bounds read information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow an attacker to disclose sensitive information about a named pipe. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. CWE-125Feb 4, 2021 | CVSS5.5v3.1 | EPSS0.887% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25246MEDIUM | An improper access control information disclosure vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG SP1, and Worry-Free Business Security could allow an unauthenticated user to create a bogus agent on an affected server that could be used then make valid configuration queries. CWE-863Feb 4, 2021 | CVSS6.5v3.1 | EPSS1.74% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25243MEDIUM | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain patch level information. CWE-200Feb 4, 2021 | CVSS5.3v3.1 | EPSS2.15% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25242MEDIUM | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain version and build information. CWE-200Feb 4, 2021 | CVSS5.3v3.1 | EPSS2.15% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25240MEDIUM | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain x64 agent hofitx information. CWE-200Feb 4, 2021 | CVSS5.3v3.1 | EPSS2.09% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25239MEDIUM | An improper access control vulnerability in Trend Micro Apex One (on-prem), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about x86 agent hotfixes. CWE-200Feb 4, 2021 | CVSS5.3v3.1 | EPSS2.09% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25238MEDIUM | An improper access control information disclosure vulnerability in Trend Micro OfficeScan XG SP1 and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about an agent's managing port. CWE-200Feb 4, 2021 | CVSS5.3v3.1 | EPSS2.08% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25235MEDIUM | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about a content inspection configuration file. CWE-200Feb 4, 2021 | CVSS5.3v3.1 | EPSS2.08% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25236MEDIUM | A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro OfficeScan XG SP1 and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to locate online agents via a specific sweep. CWE-918Feb 4, 2021 | CVSS5.3v3.1 | EPSS1.9% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25234MEDIUM | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about a specific notification configuration file. CWE-200Feb 4, 2021 | CVSS5.3v3.1 | EPSS2.07% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25233MEDIUM | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about a specific configuration download file. CWE-200Feb 4, 2021 | CVSS5.3v3.1 | EPSS2.07% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25232MEDIUM | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about the SQL database. CWE-200Feb 4, 2021 | CVSS5.3v3.1 | EPSS2.03% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25231MEDIUM | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about a specific hotfix history file. CWE-200Feb 4, 2021 | CVSS5.3v3.1 | EPSS2.15% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25230MEDIUM | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about the contents of a scan connection exception file. CWE-200Feb 4, 2021 | CVSS5.3v3.1 | EPSS2.08% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25228MEDIUM | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about hotfix history. CWE-863Feb 4, 2021 | CVSS5.3v3.1 | EPSS2.12% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2021-25229MEDIUM | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about the database server. CWE-863Feb 4, 2021 | CVSS5.3v3.1 | EPSS2.08% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |
CVE-2020-28583MEDIUM | An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal version, build and patch information. CWE-200Dec 1, 2020 | CVSS5.3v3.1 | EPSS3.21% | PoCs0 | SignalsNot listed in CISA KEVNo known ransomware useNo Nuclei templates | STIX |