Trendmicro Worry-Free Business Security vulnerabilities
58 known vulnerabilities affecting trendmicro/worry-free_business_security.
Total CVEs
58
CISA KEV
5
actively exploited
Public exploits
0
Exploited in wild
5
Severity breakdown
CRITICAL4HIGH35MEDIUM19
Vulnerabilities
Page 3 of 3
CVE-2021-25236MEDIUMCVSS 5.3v10.02021-02-04
CVE-2021-25236 [MEDIUM] CWE-918 CVE-2021-25236: A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro OfficeScan
A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro OfficeScan XG SP1 and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to locate online agents via a specific sweep.
nvd
CVE-2021-25242MEDIUMCVSS 5.3v10.02021-02-04
CVE-2021-25242 [MEDIUM] CVE-2021-25242: An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG S
An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain version and build information.
nvd
CVE-2021-25239MEDIUMCVSS 5.3v10.02021-02-04
CVE-2021-25239 [MEDIUM] CVE-2021-25239: An improper access control vulnerability in Trend Micro Apex One (on-prem), OfficeScan XG SP1, and W
An improper access control vulnerability in Trend Micro Apex One (on-prem), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about x86 agent hotfixes.
nvd
CVE-2020-28574HIGHCVSS 7.5v10.02020-11-18
CVE-2020-28574 [HIGH] CWE-22 CVE-2020-28574: A unauthenticated path traversal arbitrary remote file deletion vulnerability in Trend Micro Worry-F
A unauthenticated path traversal arbitrary remote file deletion vulnerability in Trend Micro Worry-Free Business Security 10 SP1 could allow an unauthenticated attacker to exploit the vulnerability and modify or delete arbitrary files on the product's management console.
nvd
CVE-2020-24559HIGHCVSS 7.8v10.02020-09-01
CVE-2020-24559 [HIGH] CWE-59 CVE-2020-24559: A vulnerability in Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Busine
A vulnerability in Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services on macOS may allow an attacker to manipulate a certain binary to load and run a script from a user-writable folder, which then would allow them to execute arbitrary code as root. An attacker must first obtain the ability to execute l
nvd
CVE-2020-24558HIGHCVSS 7.1v10.02020-09-01
CVE-2020-24558 [HIGH] CWE-125 CVE-2020-24558: A vulnerability in an Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Bus
A vulnerability in an Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services dll may allow an attacker to manipulate it to cause an out-of-bounds read that crashes multiple processes in the product. An attacker must first obtain the ability to execute low-privileged code on the target system in order to e
nvd
CVE-2020-24556HIGHCVSS 7.8v10.02020-09-01
CVE-2020-24556 [HIGH] CWE-59 CVE-2020-24556: A vulnerability in Trend Micro Apex One, OfficeScan XG SP1, Worry-Free Business Security 10 SP1 and
A vulnerability in Trend Micro Apex One, OfficeScan XG SP1, Worry-Free Business Security 10 SP1 and Worry-Free Business Security Services on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability
nvd
CVE-2020-24557HIGHCVSS 7.8KEVv10.02020-09-01
CVE-2020-24557 [HIGH] CVE-2020-24557: A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windo
A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function and attain privilege escalation. An attacker must first obtain the ability to execute low-privileged code on the target sys
nvd
CVE-2020-8600CRITICALCVSS 9.8v9.0v9.5+1 more2020-03-18
CVE-2020-8600 [CRITICAL] CWE-22 CVE-2020-8600: Trend Micro Worry-Free Business Security (9.0, 9.5, 10.0) is affected by a directory traversal vulne
Trend Micro Worry-Free Business Security (9.0, 9.5, 10.0) is affected by a directory traversal vulnerability that could allow an attacker to manipulate a key file to bypass authentication.
nvd
CVE-2020-8598CRITICALCVSS 9.8v9.0v9.5+1 more2020-03-18
CVE-2020-8598 [CRITICAL] CWE-306 CVE-2020-8598: Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow a remote attacker to execute arbitrary code on affected installations with SYSTEM level privileges. Authentication is not required to exploit this vulnerability.
nvd
CVE-2020-8468HIGHCVSS 8.8KEVv9.0v9.5+1 more2020-03-18
CVE-2020-8468 [HIGH] CWE-74 CVE-2020-8468: Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent client components. An attempted attack requires user authentication.
nvd
CVE-2020-8470HIGHCVSS 7.5v9.0v9.5+1 more2020-03-18
CVE-2020-8470 [HIGH] CVE-2020-8470: Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow an attacker to delete any file on the server with SYSTEM level privileges. Authentication is not required to exploit this vulnerability.
nvd
CVE-2019-18189CRITICALCVSS 9.8v9.5v10.02019-10-28
CVE-2019-18189 [CRITICAL] CWE-22 CVE-2019-18189: A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Bu
A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (11.0, XG) and Worry-Free Business Security (9.5, 10.0) may allow an attacker to bypass authentication and log on to an affected product's management console as a root user. The vulnerability does not require authentication.
nvd
CVE-2019-9489HIGHCVSS 7.5v9.5v10.02019-04-05
CVE-2019-9489 [HIGH] CWE-22 CVE-2019-9489: A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (versions XG and 11.0), and
A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (versions XG and 11.0), and Worry-Free Business Security (versions 10.0, 9.5 and 9.0) could allow an attacker to modify arbitrary files on the affected product's management console.
nvd
CVE-2018-6218HIGHCVSS 7.0v9.52018-02-16
CVE-2018-6218 [HIGH] CWE-426 CVE-2018-6218: A DLL Hijacking vulnerability in Trend Micro's User-Mode Hooking Module (UMH) could allow an attacke
A DLL Hijacking vulnerability in Trend Micro's User-Mode Hooking Module (UMH) could allow an attacker to run arbitrary code on a vulnerable system.
nvd
CVE-2016-1224MEDIUMCVSS 6.1v9.02016-06-19
CVE-2016-1224 [MEDIUM] CWE-79 CVE-2016-1224: CRLF injection vulnerability in Trend Micro Worry-Free Business Security Service 5.x and Worry-Free
CRLF injection vulnerability in Trend Micro Worry-Free Business Security Service 5.x and Worry-Free Business Security 9.0 allows remote attackers to inject arbitrary HTTP headers and conduct cross-site scripting (XSS) attacks via unspecified vectors.
nvd
CVE-2016-1223MEDIUMCVSS 5.3v9.02016-06-19
CVE-2016-1223 [MEDIUM] CWE-22 CVE-2016-1223: Directory traversal vulnerability in Trend Micro Office Scan 11.0, Worry-Free Business Security Serv
Directory traversal vulnerability in Trend Micro Office Scan 11.0, Worry-Free Business Security Service 5.x, and Worry-Free Business Security 9.0 allows remote attackers to read arbitrary files via unspecified vectors.
nvd
CVE-2008-2433CRITICALCVSS 9.8v5.02008-08-27
CVE-2008-2433 [CRITICAL] CWE-330 CVE-2008-2433: The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5
The web management console in Trend Micro OfficeScan 7.0 through 8.0, Worry-Free Business Security 5.0, and Client/Server/Messaging Suite 3.5 and 3.6 creates a random session token based only on the login time, which makes it easier for remote attackers to hijack sessions via brute-force attacks. NOTE: this can be leveraged for code execution throug
nvd
← Previous3 / 3