Improper Access Control Flaw in Trend Micro Apex One and OfficeScan XG
CVE-2021-25250
7.8HIGH
Key Information:
- Vendor
- Trend Micro
- Vendor
- CVE Published:
- 13 April 2021
Summary
An improper access control vulnerability exists in Trend Micro Apex One, Trend Micro Apex One as a Service, and OfficeScan XG SP1, allowing a local attacker to escalate privileges. Successful exploitation requires the attacker to first execute low-privileged code on the target system, targeting sensitive files. This vulnerability underscores the importance of safeguarding systems against local threats to prevent privilege escalation.
Affected Version(s)
Trend Micro Apex One 2019, SaaS
Trend Micro OfficeScan XG SP1
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved