CVE-2021-36741
Trend Micro Multiple Products Improper Input Validation Vulnerability
An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the ability to logon to the product�s management console in order to exploit this vulnerability.
HIGH · CVSS 8.8
⚠ CISA KEV
EPSS 0.00664
Act now
- Listed on CISA KEV (known exploited in the wild)
- SSVC exploitation status: active
- CVSS base score ≥ 7.0
Sigma rules7
YARA rules0