VYPR

Vendor CVEs

Trend Micro

All CVEs

684 total · sorted by risk
  • CVE-2018-6237HigMay 25, 2018
    risk 0.49cvss 7.5epss 0.06

    A vulnerability in Trend Micro Smart Protection Server (Standalone) 3.x could allow an unauthenticated remote attacker to manipulate the product to send a large number of specially crafted HTTP requests to potentially cause the file system to fill up, eventually causing a denial…

  • CVE-2017-14082HigJan 19, 2018
    risk 0.49cvss 7.5epss 0.04

    An uninitialized pointer information disclosure vulnerability in Trend Micro Mobile Security (Enterprise) versions 9.7 and below could allow an unauthenticated remote attacker to disclosure sensitive information on a vulnerable system.

  • CVE-2017-14091HigDec 16, 2017
    risk 0.49cvss 7.5epss 0.01

    A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which certain specific installations that utilize a uncommon feature - Other Update Sources - could be exploited to overwrite sensitive files in the ScanMail for Exchange directory.

  • CVE-2016-6220HigAug 7, 2017
    risk 0.49cvss 7.5epss 0.05

    Information Disclosure vulnerability in the Dashboard and Error Pages in Trend Micro Control Manager SP3 6.0.

  • CVE-2017-11382HigAug 3, 2017
    risk 0.49cvss 7.5epss 0.02

    Denial of Service vulnerability in Trend Micro Deep Discovery Email Inspector 2.5.1 allows remote attackers to delete arbitrary files on vulnerable installations, thus disabling the service. Formerly ZDI-CAN-4350.

  • CVE-2017-11390HigAug 2, 2017
    risk 0.49cvss 7.5epss 0.02

    XML external entity (XXE) processing vulnerability in Trend Micro Control Manager 6.0, if exploited, could lead to information disclosure. Formerly ZDI-CAN-4706.

  • CVE-2017-11379HigAug 1, 2017
    risk 0.49cvss 7.5epss 0.00

    Configuration and database backup archives are not signed or validated in Trend Micro Deep Discovery Director 1.1.

  • CVE-2022-27883HigApr 9, 2022
    risk 0.48cvss 7.3epss 0.01

    A link following vulnerability in Trend Micro Antivirus for Mac 11.5 could allow an attacker to create a specially-crafted file as a symlink that can lead to privilege escalation. Please note that an attacker must at least have low-level privileges on the system to attempt to…

  • CVE-2017-9035HigMay 26, 2017
    risk 0.48cvss 7.4epss 0.04

    Trend Micro ServerProtect for Linux 3.0 before CP 1531 allows attackers to eavesdrop and tamper with updates by leveraging unencrypted communications with update servers.

  • CVE-2016-8588HigApr 28, 2017
    risk 0.48cvss 7.3epss 0.02

    The hotfix_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via shell metacharacters in the file name of an uploaded file.

  • CVE-2016-8587HigApr 28, 2017
    risk 0.48cvss 7.3epss 0.02

    dlp_policy_upload.cgi in Trend Micro Threat Discovery Appliance 2.6.1062r1 and earlier allows remote authenticated users to execute arbitrary code via an archive file containing a symlink to /eng_ptn_stores/prod/sensorSDK/data/ or /eng_ptn_stores/prod/sensorSDK/backup_pol/.

  • CVE-2016-3664HigMay 23, 2016
    risk 0.48cvss 7.4epss 0.01

    Trend Micro Mobile Security for iOS before 3.2.1188 does not verify the X.509 certificate of the mobile application login server, which allows man-in-the-middle attackers to spoof this server and obtain sensitive information via a crafted certificate.

  • CVE-2024-58105HigMar 25, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security and execute arbitrary code on affected installations. This CVE address an addtional bypass not covered in CVE-2024-58104. …

  • CVE-2024-58104HigMar 25, 2025
    risk 0.47cvss 7.3epss 0.00

    A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security and execute arbitrary code on affected installations. Please note: an attacker must first obtain the ability to execute…

  • CVE-2022-28339HigFeb 22, 2025
    risk 0.47cvss 7.3epss 0.00

    Trend Micro HouseCall for Home Networks version 5.3.1302 and below contains an uncontrolled search patch element vulnerability that could allow an attacker with low user privileges to create a malicious DLL that could lead to escalated privileges.

  • CVE-2022-40143HigSep 19, 2022
    risk 0.47cvss 7.3epss 0.00

    A link following local privilege escalation vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service servers could allow a local attacker to abuse an insecure directory that could allow a low-privileged user to run arbitrary code with elevated privileges.…

  • CVE-2021-31519HigMay 12, 2021
    risk 0.47cvss 7.3epss 0.00

    An incorrect permission vulnerability in the product installer folders for Trend Micro HouseCall for Home Networks version 5.3.1179 and below could allow an attacker to escalate privileges by placing arbitrary code on a specified folder and have that code be executed by an…

  • CVE-2021-28649HigMay 12, 2021
    risk 0.47cvss 7.3epss 0.00

    An incorrect permission vulnerability in the product installer for Trend Micro HouseCall for Home Networks version 5.3.1179 and below could allow an attacker to escalate privileges by placing arbitrary code on a specified folder and have that code be executed by an Administrator…

  • CVE-2021-25251HigFeb 10, 2021
    risk 0.47cvss 7.2epss 0.02

    The Trend Micro Security 2020 and 2021 families of consumer products are vulnerable to a code injection vulnerability which could allow an attacker to disable the program's password protection and disable protection. An attacker must already have administrator privileges on the…

  • CVE-2020-8602HigAug 27, 2020
    risk 0.47cvss 7.2epss 0.04

    A vulnerability in the management consoles of Trend Micro Deep Security 10.0-12.0 and Trend Micro Vulnerability Protection 2.0 SP2 may allow an authenticated attacker with full control privileges to bypass file integrity checks, leading to remote code execution.

  • CVE-2018-6230MedMar 15, 2018
    risk 0.47cvss 6.8epss 0.03

    A SQL injection vulnerability in an Trend Micro Email Encryption Gateway 5.5 search configuration script could allow an attacker to execute SQL commands to upload and execute arbitrary code that may harm the target system.

  • CVE-2017-11396HigSep 22, 2017
    risk 0.47cvss 7.2epss 0.03

    Vulnerability issues with the web service inspection of input parameters in Trend Micro Web Security Virtual Appliance 6.5 may allow potential attackers who already have administration rights to the console to implement remote code injections.

  • CVE-2025-71215HigMay 21, 2026
    risk 0.46cvss 7.0epss 0.00

    A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent iCore service signature verification could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute…

  • CVE-2025-30680HigJun 17, 2025
    risk 0.46cvss 7.1epss 0.00

    A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (SaaS) could allow an attacker to manipulate certain parameters leading to information disclosure on affected installations. Please note: this vulnerability only affects the SaaS instance of Apex…

  • CVE-2025-49156HigJun 17, 2025
    risk 0.46cvss 7.0epss 0.00

    A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalation privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to…

  • CVE-2023-52331HigJan 23, 2024
    risk 0.46cvss 7.1epss 0.01

    A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central could allow an attacker to interact with internal or local services directly. Please note: an attacker must first obtain the ability to execute low-privileged code on the target…

  • CVE-2023-32555HigJun 26, 2023
    risk 0.46cvss 7.0epss 0.00

    A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations. Please note: a local attacker must first obtain the ability to execute low-privileged code on…

  • CVE-2023-32554HigJun 26, 2023
    risk 0.46cvss 7.0epss 0.00

    A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations. Please note: a local attacker must first obtain the ability to execute low-privileged code on…

  • CVE-2022-48191HigJan 20, 2023
    risk 0.46cvss 7.0epss 0.00

    A vulnerability exists in Trend Micro Maximum Security 2022 (17.7) wherein a low-privileged user can write a known malicious executable to a specific location and in the process of removal and restoral an attacker could replace an original folder with a mount point to an…

  • CVE-2022-44651HigDec 12, 2022
    risk 0.46cvss 7.0epss 0.00

    A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the…

  • CVE-2022-45797HigDec 12, 2022
    risk 0.46cvss 7.1epss 0.01

    An arbitrary file deletion vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One as a Service could allow a local attacker to escalate privileges and delete files on affected installations. Please note: an attacker must first…

  • CVE-2022-41745HigOct 10, 2022
    risk 0.46cvss 7.0epss 0.01

    An Out-of-Bounds access vulnerability in Trend Micro Apex One could allow a local attacker to create a specially crafted message to cause memory corruption on a certain service process which could lead to local privilege escalation on affected installations. Please note: an…

  • CVE-2022-41744HigOct 10, 2022
    risk 0.46cvss 7.0epss 0.00

    A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One Vulnerability Protection integrated component could allow a local attacker to escalate privileges and turn a specific working directory into a mount point on affected installations. Please note: an attacker…

  • CVE-2022-35234HigJul 30, 2022
    risk 0.46cvss 7.1epss 0.00

    Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure Vulnerability that could allow an attacker to read sensitive information from other memory locations and cause a crash on an affected machine.

  • CVE-2022-30687HigMay 27, 2022
    risk 0.46cvss 7.1epss 0.00

    Trend Micro Maximum Security 2022 is vulnerable to a link following vulnerability that could allow a low privileged local user to manipulate the product's secure erase feature to delete arbitrary files.

  • CVE-2022-23805HigFeb 4, 2022
    risk 0.46cvss 7.1epss 0.01

    A security out-of-bounds read information disclosure vulnerability in Trend Micro Worry-Free Business Security Server could allow a local attacker to send garbage data to a specific named pipe and crash the server. Please note: an attacker must first obtain the ability to…

  • CVE-2021-45442HigJan 10, 2022
    risk 0.46cvss 7.1epss 0.00

    A link following denial-of-service vulnerability in Trend Micro Worry-Free Business Security (on prem only) could allow a local attacker to overwrite arbitrary files in the context of SYSTEM. This is similar to, but not the same as CVE-2021-44024. Please note: an attacker must…

  • CVE-2021-44024HigJan 10, 2022
    risk 0.46cvss 7.1epss 0.00

    A link following denial-of-service vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to overwrite arbitrary files in the context of SYSTEM. Please note: an attacker must…

  • CVE-2021-44023HigDec 16, 2021
    risk 0.46cvss 7.1epss 0.00

    A link following denial-of-service (DoS) vulnerability in the Trend Micro Security (Consumer) 2021 familiy of products could allow an attacker to abuse the PC Health Checkup feature of the product to create symlinks that would allow modification of files which could lead to a…

  • CVE-2021-32466HigSep 29, 2021
    risk 0.46cvss 7.0epss 0.01

    An uncontrolled search path element privilege escalation vulnerability in Trend Micro HouseCall for Home Networks version 5.3.1225 and below could allow an attacker to escalate privileges by placing a custom crafted file in a specific directory to load a malicious library.…

  • CVE-2020-24558HigSep 1, 2020
    risk 0.46cvss 7.1epss 0.01

    A vulnerability in an Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services dll may allow an attacker to manipulate it to cause an out-of-bounds read that crashes multiple processes in the product. An attacker must first obtain the…

  • CVE-2019-14688HigFeb 20, 2020
    risk 0.46cvss 7.0epss 0.02

    Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product installation. The vulnerability was found to ONLY be exploitable…

  • CVE-2019-19693HigDec 20, 2019
    risk 0.46cvss 7.1epss 0.01

    The Trend Micro Security 2020 consumer family of products contains a vulnerability that could allow a local attacker to disclose sensitive information or to create a denial-of-service condition on affected installations. An attacker must first obtain the ability to execute…

  • CVE-2018-6236HigMay 25, 2018
    risk 0.46cvss 7.0epss 0.00

    A Time-of-Check Time-of-Use privilege escalation vulnerability in Trend Micro Maximum Security (Consumer) 2018 could allow a local attacker to escalate privileges on vulnerable installations due to a flaw within processing of IOCTL 0x222813 by the tmusa driver. An attacker must…

  • CVE-2018-10355HigMay 23, 2018
    risk 0.46cvss 7.0epss 0.01

    An authentication weakness vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to recover user passwords on vulnerable installations due to a flaw in the DBCrypto class. An attacker must first obtain access to the user database on the target system…

  • CVE-2018-6219MedMar 15, 2018
    risk 0.46cvss 6.5epss 0.04

    An Insecure Update via HTTP vulnerability in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to eavesdrop and tamper with certain types of update data.

  • CVE-2018-6218HigFeb 16, 2018
    risk 0.46cvss 7.0epss 0.02

    A DLL Hijacking vulnerability in Trend Micro's User-Mode Hooking Module (UMH) could allow an attacker to run arbitrary code on a vulnerable system.

  • CVE-2017-14088HigOct 6, 2017
    risk 0.46cvss 7.0epss 0.01

    Memory Corruption Privilege Escalation vulnerabilities in Trend Micro OfficeScan 11.0 and XG allows local attackers to execute arbitrary code and escalate privileges to resources normally reserved for the kernel on vulnerable installations by exploiting tmwfp.sys. An attacker…

  • CVE-2017-6339MedApr 5, 2017
    risk 0.46cvss 6.5epss 0.04

    Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 mismanages certain key and certificate data. Per IWSVA documentation, by default, IWSVA acts as a private Certificate Authority (CA) and dynamically generates digital certificates that are sent to…

  • CVE-2017-6338MedApr 5, 2017
    risk 0.46cvss 6.5epss 0.04

    Multiple Access Control issues in Trend Micro InterScan Web Security Virtual Appliance (IWSVA) 6.5 before CP 1746 allow an authenticated, remote user with low privileges like 'Reports Only' or 'Auditor' to change FTP Access Control Settings, create or modify reports, or upload…

Page 8 of 14