VYPR

Officescan

by Trend Micro

CVEs (103)

  • CVE-2017-14083HigOct 6, 2017
    risk 0.52cvss 7.5epss 0.06

    A vulnerability in Trend Micro OfficeScan 11.0 and XG allows remote unauthenticated users who can access the system to download the OfficeScan encryption file.

  • CVE-2021-32464HigAug 4, 2021
    risk 0.51cvss 7.8epss 0.01

    An incorrect permission assignment privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security Services could allow an attacker to modify a specific script before it is executed. Please note: an attacker must first obtain…

  • CVE-2021-28645HigApr 13, 2021
    risk 0.51cvss 7.8epss 0.01

    An incorrect permission assignment vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged…

  • CVE-2021-25253HigApr 13, 2021
    risk 0.51cvss 7.8epss 0.02

    An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a resource used by the service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain…

  • CVE-2021-25250HigApr 13, 2021
    risk 0.51cvss 7.8epss 0.01

    An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a sensitive file could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to…

  • CVE-2021-25249HigFeb 4, 2021
    risk 0.51cvss 7.8epss 0.00

    An out-of-bounds write information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to escalate privileges on affected installations. Please note: an…

  • CVE-2020-24562HigSep 29, 2020
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in Trend Micro OfficeScan XG SP1 on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability to execute…

  • CVE-2020-24559HigSep 1, 2020
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services on macOS may allow an attacker to manipulate a certain binary to load and run a script from a user-writable folder, which then would allow them to execute…

  • CVE-2019-9492HigJul 26, 2019
    risk 0.51cvss 7.8epss 0.01

    A DLL side-loading vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow an authenticated attacker to gain code execution and terminate the product's process - disabling endpoint protection. The attacker must have already gained authentication and have local access…

  • CVE-2020-8470HigMar 18, 2020
    risk 0.49cvss 7.5epss 0.05

    Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow an attacker to delete any file on the server with SYSTEM level privileges. Authentication is not required to exploit this…

  • CVE-2019-9489HigApr 5, 2019
    risk 0.49cvss 7.5epss 0.02

    A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (versions XG and 11.0), and Worry-Free Business Security (versions 10.0, 9.5 and 9.0) could allow an attacker to modify arbitrary files on the affected product's management console.

  • CVE-2018-18332HigDec 21, 2018
    risk 0.49cvss 7.5epss 0.01

    A Trend Micro OfficeScan XG weak file permissions vulnerability may allow an attacker to potentially manipulate permissions on some key files to modify other files and folders on vulnerable installations.

  • CVE-2018-18331HigDec 21, 2018
    risk 0.49cvss 7.5epss 0.01

    A Trend Micro OfficeScan XG weak file permissions vulnerability on a particular folder for a particular group may allow an attacker to alter the files, which could lead to other exploits on vulnerable installations.

  • CVE-2019-14688HigFeb 20, 2020
    risk 0.46cvss 7.0epss 0.02

    Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product installation. The vulnerability was found to ONLY be exploitable…

  • CVE-2018-6218HigFeb 16, 2018
    risk 0.46cvss 7.0epss 0.02

    A DLL Hijacking vulnerability in Trend Micro's User-Mode Hooking Module (UMH) could allow an attacker to run arbitrary code on a vulnerable system.

  • CVE-2017-14088HigOct 6, 2017
    risk 0.46cvss 7.0epss 0.01

    Memory Corruption Privilege Escalation vulnerabilities in Trend Micro OfficeScan 11.0 and XG allows local attackers to execute arbitrary code and escalate privileges to resources normally reserved for the kernel on vulnerable installations by exploiting tmwfp.sys. An attacker…

  • CVE-2020-8607MedAug 5, 2020
    risk 0.44cvss 6.7epss 0.01

    An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver could allow an attacker in user-mode with administrator permissions to abuse the driver to modify a kernel address that may cause a…

  • CVE-2021-25246MedFeb 4, 2021
    risk 0.42cvss 6.5epss 0.02

    An improper access control information disclosure vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG SP1, and Worry-Free Business Security could allow an unauthenticated user to create a bogus agent on an affected server that could be used then make…

  • CVE-2018-10505MedJun 8, 2018
    risk 0.41cvss 6.3epss 0.00

    A pool corruption privilege escalation vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within the processing of IOCTL 0x220008 in the TMWFP driver. An attacker must first obtain…

  • CVE-2018-10359MedJun 8, 2018
    risk 0.41cvss 6.3epss 0.00

    A pool corruption privilege escalation vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within the processing of IOCTL 0x220078 in the TMWFP driver. An attacker must first obtain…

Page 2 of 6