nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-28645 CVE-2021-28645
HIGH
Record summary
CVE-2021-28645 has a selected CVSS score of 7.8 (high).
Description
An incorrect permission assignment vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Description source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Trend Micro Apex OneBrowse Trend Micro / Trend Micro Apex One | CVE List | 2019, SaaS | affected |
Trend Micro OfficeScanBrowse Trend Micro / Trend Micro OfficeScan | CVE List | XG SP1 | affected |
References
4success.trendmicro.com
https://success.trendmicro.com/solution/000286019 success.trendmicro.com
https://success.trendmicro.com/solution/000286157 zerodayinitiative.com
https://www.zerodayinitiative.com/advisories/ZDI-21-402