VYPR
Unrated severityNVD Advisory· Published Dec 16, 2021· Updated Aug 4, 2024

CVE-2021-44023

CVE-2021-44023

Description

A link following denial-of-service (DoS) vulnerability in the Trend Micro Security (Consumer) 2021 familiy of products could allow an attacker to abuse the PC Health Checkup feature of the product to create symlinks that would allow modification of files which could lead to a denial-of-service.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A low-privilege local attacker can abuse the PC Health Checkup feature of Trend Micro Security 2021 to create symlinks and overwrite files, causing a denial-of-service.

Vulnerability

This link following denial-of-service (DoS) vulnerability exists in the PC Health Checkup component of Trend Micro Security (Consumer) 2021 family of products — specifically in versions 2021 (v17) and below, including Premium Security, Maximum Security, Internet Security, and Antivirus+ Security on Microsoft Windows. The flaw resides within the Platinum Host Service, where insufficient validation of symbolic links allows an attacker to redirect file operations to arbitrary locations on the system [1][2].

Exploitation

An attacker must first obtain the ability to execute low-privileged code on the target system. By creating a symbolic link and then triggering the PC Health Checkup feature, the attacker can abuse the service to overwrite a file at a path controlled by the symlink. The attack requires local access and low privileges but no user interaction beyond the initial code execution [1].

Impact

Successful exploitation allows the attacker to overwrite arbitrary files on the system, leading to a denial-of-service condition. The CVSS score is 6.1 (AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:H), reflecting high availability impact with no confidentiality exposure but some integrity loss [1]. Trend Micro has received no reports of active exploitation [2].

Mitigation

Trend Micro has released version 2022 (v17.7) for all affected products to resolve this vulnerability. Users should update to this version or later via the product’s automatic update mechanism or by downloading from the official site [2]. No workaround is available for unpatched installations.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.