CVE-2021-32458

Severity
7.8HIGH
EPSS
0.1%
top 77.89%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 27
Latest updateMay 24

Description

Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vulnerability which could allow an attacker to issue a specially crafted iotcl which could lead to code execution on affected devices. An attacker must first obtain the ability to execute low-privileged code on the target device in order to exploit this vulnerability.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-pf2v-6j36-j2xg: A privilege escalation vulnerability exists in the tdts2022-05-24
CVEList
CVE-2021-32458: Trend Micro Home Network Security version 62021-05-27

🕵️Threat Intelligence

2
Talos
Vulnerability Spotlight: Multiple vulnerabilities in Trend Micro Home Network Security Station2021-05-24
Talos
Vulnerability Spotlight: Multiple vulnerabilities in Trend Micro Home Network Security Station2021-05-24
CVE-2021-32458 (HIGH CVSS 7.8) | Trend Micro Home Network Security v | cvebase.io