CVE-2021-36742
KEVlargeLocal Privilege Escalation in Trend Micro Apex One, OfficeScan XG and WFBS
CISA: Trend Micro Multiple Products Improper Input Validation Vulnerability
CVE-2021-36742 is an improper input validation flaw (CWE-20) in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1. To trigger it, an attacker must first obtain the ability to execute low-privileged code on a machine running the affected Trend Micro agent; malformed input handled by the software then allows privilege escalation. Successful exploitation gives the attacker elevated local privileges with high impact on confidentiality, integrity, and availability (CVSS 3.1 7.8, AV:L/PR:L). Any organization running the affected agents — from Apex One as a Service tenants to on-premises Apex One, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 deployments — is exposed to local attackers who already have a foothold on an endpoint. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 and headlines describe hackers attempting to exploit zero-days in Apex One, though no public PoC is known and ransomware use is unknown.
What to do: Apply Trend Micro's updated builds for Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 per the vendor's advisory, which is the required action listed in CISA's KEV catalog. Prioritize patching hosts where untrusted users can already run low-privileged code (shared workstations, VDI, jump hosts) and hunt for local privilege-escalation indicators on agents not yet updated. Apex One as a Service tenants should verify with Trend Micro that the SaaS-side fix has been applied.
| Trend Micro Apex One (on-premises) | — |
| Trend Micro Apex One as a Service | — |
| Trend Micro OfficeScan XG | — |
| Trend Micro Worry-Free Business Security | 10.0 SP1 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
- Affected
- Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- trendmicro
- Products
- officescan, officescan business security, apex one, worry-free business security
- Weakness
- CWE-20
- Vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H