Trend Micro Apex One vulnerabilities

81 known vulnerabilities affecting trend_micro/trend_micro_apex_one.

Total CVEs
81
CISA KEV
4
actively exploited
Public exploits
0
Exploited in wild
4
Severity breakdown
CRITICAL2HIGH46MEDIUM33

Vulnerabilities

Page 2 of 5
CVE-2021-45231HIGHCVSS 7.8v2019, SaaS2022-01-10
CVE-2021-45231 [HIGH] CWE-59 CVE-2021-45231: A link following privilege escalation vulnerability in Trend Micro Apex One (on-prem and SaaS) and T A link following privilege escalation vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to create a specially crafted file with arbitrary content which could grant local privilege escalation on the affected system. Please note: an attacker must firs
cvelistv5nvd
CVE-2021-44024HIGHCVSS 7.1v2019, SaaS2022-01-08
CVE-2021-44024 [HIGH] CVE-2021-44024: A link following denial-of-service vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10 A link following denial-of-service vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to overwrite arbitrary files in the context of SYSTEM. Please note: an attacker must first obtain the ability to execute low-privil
cvelistv5
CVE-2021-44022MEDIUMCVSS 5.5v20192021-12-03
CVE-2021-44022 [MEDIUM] CWE-617 CVE-2021-44022: A reachable assertion vulnerability in Trend Micro Apex One could allow an attacker to crash the pro A reachable assertion vulnerability in Trend Micro Apex One could allow an attacker to crash the program on affected installations, leading to a denial-of-service (DoS). Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
cvelistv5nvd
CVE-2021-23139HIGHCVSS 7.5v20192021-10-21
CVE-2021-23139 [HIGH] CWE-476 CVE-2021-23139: A null pointer vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 could A null pointer vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 could allow an attacker to crash the CGI program on affected installations.
cvelistv5nvd
CVE-2021-42012HIGHCVSS 7.8v2019, SaaS2021-10-21
CVE-2021-42012 [HIGH] CWE-787 CVE-2021-42012: A stack-based buffer overflow vulnerability in Trend Micro Apex One, Apex One as a Service and Worry A stack-based buffer overflow vulnerability in Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerabi
cvelistv5nvd
CVE-2021-42104HIGHCVSS 7.8v2019, SaaS2021-10-21
CVE-2021-42104 [HIGH] CWE-269 CVE-2021-42104: Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Bus Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system i
cvelistv5nvd
CVE-2021-42106HIGHCVSS 7.8v2019, SaaS2021-10-21
CVE-2021-42106 [HIGH] CVE-2021-42106: Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10 Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target
cvelistv5
CVE-2021-42103HIGHCVSS 7.8v2019, SaaS2021-10-21
CVE-2021-42103 [HIGH] CVE-2021-42103: An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privile An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerabili
cvelistv5
CVE-2021-42102HIGHCVSS 7.8v2019, SaaS2021-10-21
CVE-2021-42102 [HIGH] CWE-427 CVE-2021-42102: An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Servic An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service agents could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
cvelistv5nvd
CVE-2021-42101HIGHCVSS 7.8v2019, SaaS2021-10-21
CVE-2021-42101 [HIGH] CWE-427 CVE-2021-42101: An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Servic An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This vulnerability is similar but not
cvelistv5nvd
CVE-2021-42108HIGHCVSS 7.8v2019, SaaS2021-10-21
CVE-2021-42108 [HIGH] CWE-269 CVE-2021-42108: Unnecessary privilege vulnerabilities in the Web Console of Trend Micro Apex One, Apex One as a Serv Unnecessary privilege vulnerabilities in the Web Console of Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit t
cvelistv5nvd
CVE-2021-42011HIGHCVSS 7.8v2019, SaaS2021-10-21
CVE-2021-42011 [HIGH] CWE-276 CVE-2021-42011: An incorrect permission assignment vulnerability in Trend Micro Apex One and Apex One as a Service c An incorrect permission assignment vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to load a DLL with escalated privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
cvelistv5nvd
CVE-2021-42107HIGHCVSS 7.8v2019, SaaS2021-10-21
CVE-2021-42107 [HIGH] CVE-2021-42107: Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10 Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target
cvelistv5
CVE-2021-42105HIGHCVSS 7.8v2019, SaaS2021-10-21
CVE-2021-42105 [HIGH] CVE-2021-42105: Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10 Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target
cvelistv5
CVE-2021-3848MEDIUMCVSS 5.5v2019, SaaS2021-10-06
CVE-2021-3848 [MEDIUM] CVE-2021-3848: An arbitrary file creation by privilege escalation vulnerability in Trend Micro Apex One, Apex One a An arbitrary file creation by privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1, and Worry-Free Business Security Services could allow a local attacker to create an arbitrary file with higher privileges that could lead to a denial-of-service (DoS) on affected installations. Please note: an
cvelistv5nvd
CVE-2021-32465HIGHCVSS 8.8v2019, SaaS2021-08-04
CVE-2021-32465 [HIGH] CWE-281 CVE-2021-32465: An incorrect permission preservation vulnerability in Trend Micro Apex One, Apex One as a Service an An incorrect permission preservation vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a remote user to perform an attack and bypass authentication on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this v
cvelistv5nvd
CVE-2021-32464HIGHCVSS 7.8v2019, SaaS2021-08-04
CVE-2021-32464 [HIGH] CWE-276 CVE-2021-32464: An incorrect permission assignment privilege escalation vulnerability in Trend Micro Apex One, Apex An incorrect permission assignment privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security Services could allow an attacker to modify a specific script before it is executed. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to e
cvelistv5nvd
CVE-2021-36742HIGHCVSS 7.8KEVv2019, SaaS2021-07-29
CVE-2021-36742 [HIGH] CWE-20 CVE-2021-36742: A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vu
cvelistv5nvd
CVE-2021-36741HIGHCVSS 8.8KEVv2019, SaaS2021-07-29
CVE-2021-36741 [HIGH] CWE-434 CVE-2021-36741: An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeSca An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the ability to logon to the product�s management console in order to exploit this vu
cvelistv5nvd
CVE-2021-32463HIGHCVSS 7.8v2019, SaaS2021-07-20
CVE-2021-32463 [HIGH] CWE-732 CVE-2021-32463: An incorrect permission assignment denial-of-service vulnerability in Trend Micro Apex One, Apex One An incorrect permission assignment denial-of-service vulnerability in Trend Micro Apex One, Apex One as a Service (SaaS), Worry-Free Business Security 10.0 SP1 and Worry-Free Servgices could allow a local attacker to escalate privileges and delete files with system privileges on affected installations. Please note: an attacker must first obtain the ab
cvelistv5nvd