Junglewise Threat Intelligence

CVE-2021-36741: Trend Micro Multiple Products Improper Input Validation Vulnerability

CVE-2021-36741 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Vendors: Trend Micro.

Executive brief

An improper input validation vulnerability in multiple Trend Micro endpoint security products allows a remote attacker with management console access to upload arbitrary files. This vulnerability affects Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1.

Affected products

  • Trend Micro Apex One
  • Trend Micro Apex One as a Service
  • Trend Micro OfficeScan XG
  • Trend Micro Worry-Free Business Security 10.0 SP1

Timeline

  • 2021-11-03: disclosed
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported as exploited in the wild.