CVE-2021-32466

HIGH

Trend Micro HouseCall for Home Networks <= 5.3.1225 - Privilege Escalation via Uncontrolled Search Path Element

Title source: llm
STIX 2.1

Description

An uncontrolled search path element privilege escalation vulnerability in Trend Micro HouseCall for Home Networks version 5.3.1225 and below could allow an attacker to escalate privileges by placing a custom crafted file in a specific directory to load a malicious library. Please note that an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.

References (3)

Core 3
Core References
Patch, Vendor Advisory x_refsource_misc
https://helpcenter.trendmicro.com/ja-jp/article/TMKA-10621
Third Party Advisory, VDB Entry x_refsource_misc
https://www.zerodayinitiative.com/advisories/ZDI-21-1112/

Scores

CVSS v3 7.0
EPSS 0.0023
EPSS Percentile 45.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-427
Status published
Products (1)
trendmicro/housecall_for_home_networks < 5.3.1225
Published Sep 29, 2021
Tracked Since Feb 18, 2026