Denial-of-Service Vulnerability in Worry-Free Business Security by Trend Micro
CVE-2021-45442
7.1HIGH
Key Information:
- Vendor
- Trend Micro
- Vendor
- CVE Published:
- 10 January 2022
Summary
A denial-of-service vulnerability in Trend Micro Worry-Free Business Security (on premise only) may enable a local attacker to overwrite arbitrary files with SYSTEM privileges. Prior to exploiting this vulnerability, an attacker must gain access to execute low-privileged code on the targeted system. This flaw poses a risk similar to other CVEs and necessitates immediate attention from organizations utilizing this software to mitigate potential exploitation.
Affected Version(s)
Trend Micro Worry-Free Business Security 10.0 SP1
References
CVSS V3.1
Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved