Junglewise Threat Intelligence

CVE-2021-36742: Trend Micro Multiple Products Improper Input Validation Vulnerability

CVE-2021-36742 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2021-11-03

Vendors: Trend Micro.

Executive brief

An improper input validation vulnerability in multiple Trend Micro security products allows a local attacker to escalate privileges. To exploit this, an attacker must already have the ability to execute low-privileged code on the target system.

Affected products

  • Trend Micro Apex One 2019
  • Trend Micro Apex One as a Service
  • Trend Micro OfficeScan XG SP1
  • Trend Micro Worry-Free Business Security 10.0 SP1

Timeline

  • 2021-07-29: disclosed: NVD Published Date
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported as exploited in the wild in CISA KEV catalog