VYPR

Vendor CVEs

Trend Micro

All CVEs

684 total · sorted by risk
  • CVE-2021-42106HigOct 21, 2021
    risk 0.51cvss 7.8epss 0.00

    Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must…

  • CVE-2021-42105HigOct 21, 2021
    risk 0.51cvss 7.8epss 0.00

    Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must…

  • CVE-2021-42104HigOct 21, 2021
    risk 0.51cvss 7.8epss 0.00

    Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must…

  • CVE-2021-42103HigOct 21, 2021
    risk 0.51cvss 7.8epss 0.00

    An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in…

  • CVE-2021-42102HigOct 21, 2021
    risk 0.51cvss 7.8epss 0.00

    An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service agents could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target…

  • CVE-2021-42101HigOct 21, 2021
    risk 0.51cvss 7.8epss 0.00

    An uncontrolled search path element vulnerabilities in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. An attacker must first obtain the ability to execute low-privileged code on the target system in…

  • CVE-2021-42012HigOct 21, 2021
    risk 0.51cvss 7.8epss 0.01

    A stack-based buffer overflow vulnerability in Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute…

  • CVE-2021-42011HigOct 21, 2021
    risk 0.51cvss 7.8epss 0.00

    An incorrect permission assignment vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to load a DLL with escalated privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged…

  • CVE-2021-36744HigSep 6, 2021
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Security (Consumer) 2021 and 2020 are vulnerable to a directory junction vulnerability which could allow an attacker to exploit the system to escalate privileges and create a denial of service.

  • CVE-2021-32464HigAug 4, 2021
    risk 0.51cvss 7.8epss 0.01

    An incorrect permission assignment privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security Services could allow an attacker to modify a specific script before it is executed. Please note: an attacker must first obtain…

  • CVE-2021-32463HigJul 20, 2021
    risk 0.51cvss 7.8epss 0.00

    An incorrect permission assignment denial-of-service vulnerability in Trend Micro Apex One, Apex One as a Service (SaaS), Worry-Free Business Security 10.0 SP1 and Worry-Free Servgices could allow a local attacker to escalate privileges and delete files with system privileges on…

  • CVE-2021-32461HigJul 8, 2021
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Password Manager (Consumer) version 5.0.0.1217 and below is vulnerable to an Integer Truncation Privilege Escalation vulnerability which could allow a local attacker to trigger a buffer overflow and escalate privileges on affected installations. An attacker must…

  • CVE-2021-32460HigJun 3, 2021
    risk 0.51cvss 7.8epss 0.00

    The Trend Micro Maximum Security 2021 (v17) consumer product is vulnerable to an improper access control vulnerability in the installer which could allow a local attacker to escalate privileges on a target machine. Please note than an attacker must already have local user…

  • CVE-2021-32458HigMay 27, 2021
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vulnerability which could allow an attacker to issue a specially crafted iotcl which could lead to code execution on affected devices. An attacker must first…

  • CVE-2021-32457HigMay 26, 2021
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vulnerability which could allow an attacker to issue a specially crafted iotcl to escalate privileges on affected devices. An attacker must first obtain the…

  • CVE-2021-28648HigApr 22, 2021
    risk 0.51cvss 7.8epss 0.01

    Trend Micro Antivirus for Mac 2020 v10.5 and 2021 v11 (Consumer) is vulnerable to an improper access control privilege escalation vulnerability that could allow an attacker to establish a connection that could lead to full local privilege escalation within the application.…

  • CVE-2021-28647HigApr 13, 2021
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Password Manager version 5 (Consumer) is vulnerable to a DLL Hijacking vulnerability which could allow an attacker to inject a malicious DLL file during the installation progress and could execute a malicious program each time a user installs a program.

  • CVE-2021-28645HigApr 13, 2021
    risk 0.51cvss 7.8epss 0.01

    An incorrect permission assignment vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged…

  • CVE-2021-25253HigApr 13, 2021
    risk 0.51cvss 7.8epss 0.02

    An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a resource used by the service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain…

  • CVE-2021-25250HigApr 13, 2021
    risk 0.51cvss 7.8epss 0.01

    An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a sensitive file could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to…

  • CVE-2021-25249HigFeb 4, 2021
    risk 0.51cvss 7.8epss 0.00

    An out-of-bounds write information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to escalate privileges on affected installations. Please note: an…

  • CVE-2021-25247HigJan 27, 2021
    risk 0.51cvss 7.8epss 0.01

    A DLL hijacking vulnerability Trend Micro HouseCall for Home Networks version 5.3.1063 and below could allow an attacker to use a malicious DLL to escalate privileges and perform arbitrary code execution. An attacker must already have user privileges on the machine to exploit…

  • CVE-2020-28572HigNov 18, 2020
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in Trend Micro Apex One could allow an unprivileged user to abuse the product installer to reinstall the agent with additional malicious code in the context of a higher privilege.

  • CVE-2020-27697HigNov 18, 2020
    risk 0.51cvss 7.8epss 0.01

    Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a malicious DLL in a non-protected location with high privileges (symlink attack) which can lead to obtaining administrative privileges during the…

  • CVE-2020-27696HigNov 18, 2020
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a specific Windows system directory which can lead to obtaining administrative privileges during the installation of the product.

  • CVE-2020-27695HigNov 18, 2020
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Security 2020 (Consumer) contains a vulnerability in the installer package that could be exploited by placing a malicious DLL in a local directory which can lead to obtaining administrative privileges during the installation of the product.

  • CVE-2020-25776HigOct 2, 2020
    risk 0.51cvss 7.8epss 0.01

    Trend Micro Antivirus for Mac 2020 (Consumer) is vulnerable to a symbolic link privilege escalation attack where an attacker could exploit a critical file on the system to escalate their privileges. An attacker must first obtain the ability to execute low-privileged code on the…

  • CVE-2020-25773HigSep 29, 2020
    risk 0.51cvss 7.8epss 0.02

    A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to execute arbitrary code on affected products. User interaction is required to exploit this vulnerability in that the target must import a corrupted configuration file.

  • CVE-2020-24563HigSep 29, 2020
    risk 0.51cvss 7.8epss 0.00

    A vulnerability in Trend Micro Apex One may allow a local attacker to manipulate the process of the security agent unload option (if configured), which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability to…

  • CVE-2020-24562HigSep 29, 2020
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in Trend Micro OfficeScan XG SP1 on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability to execute…

  • CVE-2020-24559HigSep 1, 2020
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services on macOS may allow an attacker to manipulate a certain binary to load and run a script from a user-writable folder, which then would allow them to execute…

  • CVE-2020-24556HigSep 1, 2020
    risk 0.51cvss 7.8epss 0.01

    A vulnerability in Trend Micro Apex One, OfficeScan XG SP1, Worry-Free Business Security 10 SP1 and Worry-Free Business Security Services on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a…

  • CVE-2020-15602HigJul 15, 2020
    risk 0.51cvss 7.8epss 0.01

    An untrusted search path remote code execution (RCE) vulnerability in the Trend Micro Secuity 2020 (v16.0.0.1146 and below) consumer family of products could allow an attacker to run arbitrary code on a vulnerable system. As the Trend Micro installer tries to load DLL files from…

  • CVE-2020-8469HigMar 12, 2020
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Password Manager for Windows version 5.0 is affected by a DLL hijacking vulnerability would could potentially allow an attacker privleged escalation.

  • CVE-2020-8601HigFeb 20, 2020
    risk 0.51cvss 7.8epss 0.00

    Trend Micro Vulnerability Protection 2.0 is affected by a vulnerability that could allow an attack to use the product installer to load other DLL files located in the same directory.

  • CVE-2019-20358HigJan 30, 2020
    risk 0.51cvss 7.8epss 0.05

    Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed. Another attack vector similar to…

  • CVE-2019-20357HigJan 18, 2020
    risk 0.51cvss 7.8epss 0.01

    A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious program to escalate privileges and attain persistence on a…

  • CVE-2019-19689HigDec 18, 2019
    risk 0.51cvss 7.8epss 0.01

    Trend Micro HouseCall for Home Networks (versions below 5.3.0.1063) could be exploited via a DLL Hijack related to a vulnerability on the packer that the program uses.

  • CVE-2019-19688HigDec 18, 2019
    risk 0.51cvss 7.8epss 0.01

    A privilege escalation vulnerability in Trend Micro HouseCall for Home Networks (versions below 5.3.0.1063) could be exploited allowing an attacker to place a malicious DLL file into the application directory and elevate privileges.

  • CVE-2019-15628HigDec 2, 2019
    risk 0.51cvss 7.8epss 0.01

    Trend Micro Security (Consumer) 2020 (v16.0.1221 and below) is affected by a DLL hijacking vulnerability that could allow an attacker to use a specific service as an execution and/or persistence mechanism which could execute a malicious program each time the service is started.

  • CVE-2019-14686HigAug 21, 2019
    risk 0.51cvss 7.8epss 0.01

    A DLL hijacking vulnerability exists in the Trend Micro Security's 2019 consumer family of products (v15) Folder Shield component and the standalone Trend Micro Ransom Buster (1.0) tool in which, if exploited, would allow an attacker to load a malicious DLL, leading to elevated…

  • CVE-2019-14685HigAug 21, 2019
    risk 0.51cvss 7.8epss 0.01

    A local privilege escalation vulnerability exists in Trend Micro Security 2019 (v15.0) in which, if exploited, would allow an attacker to manipulate a specific product feature to load a malicious service.

  • CVE-2019-14687HigAug 20, 2019
    risk 0.51cvss 7.8epss 0.02

    A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14684.

  • CVE-2019-14684HigAug 20, 2019
    risk 0.51cvss 7.8epss 0.01

    A DLL hijacking vulnerability exists in Trend Micro Password Manager 5.0 in which, if exploited, would allow an attacker to load an arbitrary unsigned DLL into the signed service's process. This process is very similar, yet not identical to CVE-2019-14687.

  • CVE-2019-9492HigJul 26, 2019
    risk 0.51cvss 7.8epss 0.01

    A DLL side-loading vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow an authenticated attacker to gain code execution and terminate the product's process - disabling endpoint protection. The attacker must have already gained authentication and have local access…

  • CVE-2018-18333HigFeb 5, 2019
    risk 0.51cvss 7.8epss 0.02

    A DLL hijacking vulnerability in Trend Micro Security 2019 (Consumer) versions below 15.0.0.1163 and below could allow an attacker to manipulate a specific DLL and escalate privileges on vulnerable installations.

  • CVE-2018-18329HigOct 23, 2018
    risk 0.51cvss 7.8epss 0.01

    A KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer) 7.0 (2017) and above could allow a local attacker to escalate privileges on vulnerable installations. The issue results from the lack of proper validation…

  • CVE-2018-18328HigOct 23, 2018
    risk 0.51cvss 7.8epss 0.01

    A KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer) 7.0 (2017) and above could allow a local attacker to escalate privileges on vulnerable installations. The issue results from the lack of proper validation…

  • CVE-2018-18327HigOct 23, 2018
    risk 0.51cvss 7.8epss 0.01

    A KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer) 7.0 (2017) and above could allow a local attacker to escalate privileges on vulnerable installations. The issue results from the lack of proper validation…

  • CVE-2018-15367HigOct 23, 2018
    risk 0.51cvss 7.8epss 0.01

    A ctl_set KERedirect Untrusted Pointer Dereference Privilege Escalation vulnerability in Trend Micro Antivirus for Mac (Consumer) 7.0 (2017) and above could allow a local attacker to escalate privileges on vulnerable installations. An attacker must first obtain the ability to…

Page 6 of 14