Denial-of-Service Vulnerability in Worry-Free Business Security by Trend Micro
CVE-2021-45442

7.1HIGH

Key Information:

Vendor
CVE Published:
10 January 2022

Summary

A denial-of-service vulnerability in Trend Micro Worry-Free Business Security (on premise only) may enable a local attacker to overwrite arbitrary files with SYSTEM privileges. Prior to exploiting this vulnerability, an attacker must gain access to execute low-privileged code on the targeted system. This flaw poses a risk similar to other CVEs and necessitates immediate attention from organizations utilizing this software to mitigate potential exploitation.

Affected Version(s)

Trend Micro Worry-Free Business Security 10.0 SP1

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.