EXPOSURES › CVE-2021-36742
CVE-2021-36742
HIGH ⌖ ON CISA KEV · EXPLOITEDTrend Micro Apex One and Worry-Free Business Security suffered an improper input validation flaw enabling privilege escalation.
The improper input validation vulnerability in Trend Micro's Apex One and Worry-Free Business Security allowed attackers to escalate privileges, potentially compromising the entire system. DIB organizations must ensure these products are patched immediately, as the flaw was actively exploited in the wild. This failure highlights the risk of relying on security software with known, unpatched vulnerabilities.
Shame score — A privilege escalation flaw in critical endpoint security software that was actively exploited in the wild, indicating a failure to patch known vulnerabilities before they were weaponized.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows for privilege escalation.
"Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows for privilege escalation."
| PRODUCT | STATUS |
|---|---|
| Trend Micro Cloud One for Government Trend Micro Inc. |
In Process |
| Trend Micro Vision One for Government Trend Micro Inc. |
In Process |