Out-of-Bounds Write Vulnerability in Trend Micro Apex One and OfficeScan Products
CVE-2021-25249
7.8HIGH
Key Information:
- Vendor
Trend Micro
- Vendor
- CVE Published:
- 4 February 2021
What is CVE-2021-25249?
An out-of-bounds write vulnerability exists in Trend Micro's Apex One, OfficeScan XG SP1, and Worry-Free Business Security products. This flaw could allow a local attacker to escalate privileges on affected installations. The attacker must first have access to execute low-privileged code on the targeted system to exploit this vulnerability, potentially leading to sensitive information disclosure and increased privileges.
Affected Version(s)
Trend Micro Apex One 2019, SaaS
Trend Micro OfficeScan XG SP1
Trend Micro Worry-Free Business Security 10.0 SP1, Services (SaaS)