CVE-2021-28648

HIGH

Trend Micro Antivirus 10.5-10.5.2088 - Privilege Escalation via Improper Access Control

Title source: llm
STIX 2.1

Description

Trend Micro Antivirus for Mac 2020 v10.5 and 2021 v11 (Consumer) is vulnerable to an improper access control privilege escalation vulnerability that could allow an attacker to establish a connection that could lead to full local privilege escalation within the application. Please note that an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.

References (2)

Core 2
Core References
Patch, Vendor Advisory x_refsource_misc
https://helpcenter.trendmicro.com/en-us/article/TMKA-10293
Third Party Advisory, VDB Entry x_refsource_misc
https://www.zerodayinitiative.com/advisories/ZDI-21-420/

Scores

CVSS v3 7.8
EPSS 0.0008
EPSS Percentile 23.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

Status published
Products (1)
trendmicro/antivirus 10.5 - 10.5.2088
Published Apr 22, 2021
Tracked Since Feb 18, 2026