Executive brief
An improper input validation vulnerability in multiple Trend Micro security products allows a local attacker to escalate privileges. To exploit this, an attacker must already have the ability to execute low-privileged code on the target system.
Affected products
- Trend Micro Apex One 2019
- Trend Micro Apex One as a Service
- Trend Micro OfficeScan XG SP1
- Trend Micro Worry-Free Business Security 10.0 SP1
Timeline
- 2021-07-29: disclosed: NVD Published Date
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Reported as exploited in the wild in CISA KEV catalog