CVE-2021-36741
KEVlargeAuthenticated Arbitrary File Upload in Trend Micro Apex One and OfficeScan Consoles
CISA: Trend Micro Multiple Products Improper Input Validation Vulnerability
CVE-2021-36741 is an improper input validation flaw (CWE-434) in the management consoles of Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 that permits the upload of arbitrary files on affected installations. It is triggered remotely over the network (CVSS AV:N) by an attacker who has first obtained logon access to the product's management console (PR:L), with no user interaction required. Successful exploitation lets the attacker place arbitrary files on the management server, with high potential impact to confidentiality, integrity, and availability (CVSS 3.1 score 8.8). Organizations running any of these Trend Micro endpoint-security consoles are affected, including tenants of the cloud-hosted Apex One as a Service. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), indicating known in-the-wild exploitation; no public proof-of-concept is known, ransomware use is unconfirmed, and news reports indicate attackers attempted to exploit zero-days in the Trend Micro Apex One platform.
What to do: Apply Trend Micro's patches to on-premises Apex One, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 per the vendor advisories and CISA's required action, and confirm the Apex One as a Service-hosted console has been updated by Trend Micro. Because exploitation requires an authenticated console session, restrict management-console logon to trusted administrators, use strong credentials/MFA, and audit console logs for unexpected file uploads or unfamiliar sessions. Treat any internet-exposed management console as higher risk and prioritize patching it.
| Trend Micro Apex One (on-premises) | — |
| Trend Micro Apex One as a Service | hosted SaaS service (no local version applies) |
| Trend Micro OfficeScan XG | — |
| Trend Micro Worry-Free Business Security | 10.0 SP1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the ability to logon to the product�s management console in order to exploit this vulnerability.
- Affected
- Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- trendmicro
- Products
- officescan, officescan business security, apex one, worry-free business security
- Weakness
- CWE-434
- Vector
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H