Executive brief
Trend Micro Apex One, OfficeScan, and Worry-Free Business Security on Windows contain an improper access control vulnerability. A local attacker with low-privileged code execution can manipulate specific product folders to disable security features and abuse Windows functions to achieve privilege escalation.
Affected products
- Trend Micro Apex One 2019, SaaS
- Trend Micro Worry-Free Business Security 10.0 SP1
- Trend Micro OfficeScan
Timeline
- 2020-09-08: disclosed: Initial NVD analysis date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Confirmed exploited in the wild per CISA KEV catalog entry date