CVE-2021-36741

An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the ability to logon to the product?s management console in order to exploit this vulnerability.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:trendmicro:officescan:xg:sp1:*:*:*:*:*:*
cpe:2.3:a:trendmicro:officescan_business_security:10.0:sp1:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:worry-free_business_security:10.0:sp1:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

14 Aug 2024, 15:14

Type Values Removed Values Added
CWE CWE-20 CWE-434
Summary (en) An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the ability to logon to the product�s management console in order to exploit this vulnerability. (en) An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the ability to logon to the product?s management console in order to exploit this vulnerability.

04 Aug 2024, 01:15

Type Values Removed Values Added
Summary (en) An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the ability to logon to the product?s management console in order to exploit this vulnerability. (en) An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the ability to logon to the product�s management console in order to exploit this vulnerability.
Summary (es) Una vulnerabilidad de comprobación de entrada inapropiada en Trend Micro Apex One, Apex One as a Service, OfficeScan XG y Worry-Free Business Security versión 10.0 SP1, permite a un adjunto remoto cargar archivos arbitrarios en las instalaciones afectadas. Nota: un atacante debe obtener primero la habilidad de iniciar sesión en la consola de administración del producto para poder explotar esta vulnerabilidad (es) Una vulnerabilidad de validación de entrada incorrecta en Trend Micro Apex One, Apex One as a Service, OfficeScan XG y Worry-Free Business Security 10.0 SP1 permite que un control remoto conectado cargue archivos arbitrarios en las instalaciones afectadas. Tenga en cuenta: un atacante primero debe obtener la capacidad de iniciar sesión en la consola de administración del producto para poder aprovechar esta vulnerabilidad.

26 Jul 2024, 19:26

Type Values Removed Values Added
Summary (en) An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the ability to logon to the product�s management console in order to exploit this vulnerability. (en) An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the ability to logon to the product?s management console in order to exploit this vulnerability.
References () https://success.trendmicro.com/jp/solution/000287796 - Vendor Advisory () https://success.trendmicro.com/jp/solution/000287796 - Broken Link, Vendor Advisory
References () https://success.trendmicro.com/jp/solution/000287815 - Vendor Advisory () https://success.trendmicro.com/jp/solution/000287815 - Broken Link, Vendor Advisory
References () https://success.trendmicro.com/solution/000287819 - Vendor Advisory () https://success.trendmicro.com/solution/000287819 - Broken Link, Vendor Advisory
References () https://success.trendmicro.com/solution/000287820 - Vendor Advisory () https://success.trendmicro.com/solution/000287820 - Broken Link, Vendor Advisory

Information

Published : 2021-07-29 20:15

Updated : 2024-08-14 15:14


NVD link : CVE-2021-36741

Mitre link : CVE-2021-36741

CVE.ORG link : CVE-2021-36741


JSON object : View

Products Affected

trendmicro

  • officescan_business_security
  • worry-free_business_security
  • apex_one
  • officescan

microsoft

  • windows
CWE
CWE-434

Unrestricted Upload of File with Dangerous Type