ZeroHour

CVE-2021-36741

KEVlarge

Authenticated Arbitrary File Upload in Trend Micro Apex One and OfficeScan Consoles

CISA: Trend Micro Multiple Products Improper Input Validation Vulnerability

CVSS 3.1
8.8 high
EPSS
5%p92
Published
()
KEV added
AI analysis

CVE-2021-36741 is an improper input validation flaw (CWE-434) in the management consoles of Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 that permits the upload of arbitrary files on affected installations. It is triggered remotely over the network (CVSS AV:N) by an attacker who has first obtained logon access to the product's management console (PR:L), with no user interaction required. Successful exploitation lets the attacker place arbitrary files on the management server, with high potential impact to confidentiality, integrity, and availability (CVSS 3.1 score 8.8). Organizations running any of these Trend Micro endpoint-security consoles are affected, including tenants of the cloud-hosted Apex One as a Service. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), indicating known in-the-wild exploitation; no public proof-of-concept is known, ransomware use is unconfirmed, and news reports indicate attackers attempted to exploit zero-days in the Trend Micro Apex One platform.

What to do: Apply Trend Micro's patches to on-premises Apex One, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 per the vendor advisories and CISA's required action, and confirm the Apex One as a Service-hosted console has been updated by Trend Micro. Because exploitation requires an authenticated console session, restrict management-console logon to trusted administrators, use strong credentials/MFA, and audit console logs for unexpected file uploads or unfamiliar sessions. Treat any internet-exposed management console as higher risk and prioritize patching it.

Affected
Trend Micro Apex One (on-premises)
Trend Micro Apex One as a Servicehosted SaaS service (no local version applies)
Trend Micro OfficeScan XG
Trend Micro Worry-Free Business Security10.0 SP1
Estimated exposure
largelikely tens of thousands of management console deployments worldwide across the four products, plus all Apex One as a Service tenants (order-of-magnitude… — Trend Micro's OfficeScan, Apex One and Worry-Free consoles are widely deployed enterprise and SMB endpoint-security management servers for which no public install counts exist, and the SaaS variant is centrally hosted, so on-premises…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected installations. Please note: an attacker must first obtain the ability to logon to the product�s management console in order to exploit this vulnerability.

CISA Known Exploited Vulnerability
Affected
Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
trendmicro
Products
officescan, officescan business security, apex one, worry-free business security
Weakness
CWE-434
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news