Directory Junction Vulnerability in Trend Micro Security Software
CVE-2021-36744

7.8HIGH

Key Information:

Vendor
CVE Published:
6 September 2021

Summary

Trend Micro Security (Consumer) versions 2021 and 2020 are exposed to a directory junction vulnerability that could enable an attacker to escalate privileges on a compromised system. This exploitation could lead to unauthorized access, allowing attackers to manipulate files or processes. In addition, the vulnerability poses a risk of creating a denial of service, significantly impacting system availability and integrity.

Affected Version(s)

Trend Micro Security (Consumer) 2019, 2020, 2021

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.