CVE-2021-44023

HIGH

Trend Micro Security 2021 < 17.0 - Denial of Service via PC Health Checkup Symlink Abuse

Title source: llm
STIX 2.1

Description

A link following denial-of-service (DoS) vulnerability in the Trend Micro Security (Consumer) 2021 familiy of products could allow an attacker to abuse the PC Health Checkup feature of the product to create symlinks that would allow modification of files which could lead to a denial-of-service.

References (2)

Core 2
Core References
Third Party Advisory, VDB Entry x_refsource_misc
https://www.zerodayinitiative.com/advisories/ZDI-21-1536/

Scores

CVSS v3 7.1
EPSS 0.0021
EPSS Percentile 43.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Details

CWE
CWE-59
Status published
Products (4)
trendmicro/antivirus\+_security_2021 < 17.0
trendmicro/internet_security_2021 < 17.0
trendmicro/maximum_security_2021 < 17.0
trendmicro/premium_security_2021 < 17.0
Published Dec 16, 2021
Tracked Since Feb 18, 2026