Improper Access Control Flaw in Trend Micro Apex One and OfficeScan XG
CVE-2021-25250
7.8HIGH
Key Information:
- Vendor
Trend Micro
- Vendor
- CVE Published:
- 13 April 2021
What is CVE-2021-25250?
An improper access control vulnerability exists in Trend Micro Apex One, Trend Micro Apex One as a Service, and OfficeScan XG SP1, allowing a local attacker to escalate privileges. Successful exploitation requires the attacker to first execute low-privileged code on the target system, targeting sensitive files. This vulnerability underscores the importance of safeguarding systems against local threats to prevent privilege escalation.
Affected Version(s)
Trend Micro Apex One 2019, SaaS
Trend Micro OfficeScan XG SP1