Executive brief
An improper input validation vulnerability in multiple Trend Micro endpoint security products allows a remote attacker with management console access to upload arbitrary files. This vulnerability affects Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1.
Affected products
- Trend Micro Apex One
- Trend Micro Apex One as a Service
- Trend Micro OfficeScan XG
- Trend Micro Worry-Free Business Security 10.0 SP1
Timeline
- 2021-11-03: disclosed
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Reported as exploited in the wild.