Improper Access Control Flaw in Trend Micro Apex One and OfficeScan XG
CVE-2021-25250

7.8HIGH

Key Information:

Vendor
CVE Published:
13 April 2021

Summary

An improper access control vulnerability exists in Trend Micro Apex One, Trend Micro Apex One as a Service, and OfficeScan XG SP1, allowing a local attacker to escalate privileges. Successful exploitation requires the attacker to first execute low-privileged code on the target system, targeting sensitive files. This vulnerability underscores the importance of safeguarding systems against local threats to prevent privilege escalation.

Affected Version(s)

Trend Micro Apex One 2019, SaaS

Trend Micro OfficeScan XG SP1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.