CVE-2021-25251

CWE-94Code Injection3 documents3 sources
Severity
7.2HIGH
EPSS
0.9%
top 24.95%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 10
Latest updateMay 24

Description

The Trend Micro Security 2020 and 2021 families of consumer products are vulnerable to a code injection vulnerability which could allow an attacker to disable the program's password protection and disable protection. An attacker must already have administrator privileges on the machine to exploit this vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HExploitability: 1.2 | Impact: 5.9

🔴Vulnerability Details

2
GHSA
GHSA-3pw2-j2vj-ghmp: The Trend Micro Security 2020 and 2021 families of consumer products are vulnerable to a code injection vulnerability which could allow an attacker to2022-05-24
CVEList
CVE-2021-25251: The Trend Micro Security 2020 and 2021 families of consumer products are vulnerable to a code injection vulnerability which could allow an attacker to2021-02-10
CVE-2021-25251 (HIGH CVSS 7.2) | The Trend Micro Security 2020 and 2 | cvebase.io