ZeroHour

CVE-2021-36742

KEVlarge

Local Privilege Escalation in Trend Micro Apex One, OfficeScan XG and WFBS

CISA: Trend Micro Multiple Products Improper Input Validation Vulnerability

CVSS 3.1
7.8 high
EPSS
1%p73
Published
()
KEV added
AI analysis

CVE-2021-36742 is an improper input validation flaw (CWE-20) in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1. To trigger it, an attacker must first obtain the ability to execute low-privileged code on a machine running the affected Trend Micro agent; malformed input handled by the software then allows privilege escalation. Successful exploitation gives the attacker elevated local privileges with high impact on confidentiality, integrity, and availability (CVSS 3.1 7.8, AV:L/PR:L). Any organization running the affected agents — from Apex One as a Service tenants to on-premises Apex One, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 deployments — is exposed to local attackers who already have a foothold on an endpoint. Exploitation is confirmed in the wild: the flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2021-11-03 and headlines describe hackers attempting to exploit zero-days in Apex One, though no public PoC is known and ransomware use is unknown.

What to do: Apply Trend Micro's updated builds for Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 per the vendor's advisory, which is the required action listed in CISA's KEV catalog. Prioritize patching hosts where untrusted users can already run low-privileged code (shared workstations, VDI, jump hosts) and hunt for local privilege-escalation indicators on agents not yet updated. Apex One as a Service tenants should verify with Trend Micro that the SaaS-side fix has been applied.

Affected
Trend Micro Apex One (on-premises)
Trend Micro Apex One as a Service
Trend Micro OfficeScan XG
Trend Micro Worry-Free Business Security10.0 SP1
Estimated exposure
largelikely tens of thousands of enterprise deployments, plausibly hundreds of thousands of protected endpoints — No install counts are in the source data, so this order-of-magnitude estimate is based on the broad enterprise and SMB deployment patterns of Trend Micro's endpoint agents (Apex One, OfficeScan, WFBS), with the SaaS variant extending…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

CISA Known Exploited Vulnerability
Affected
Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
trendmicro
Products
officescan, officescan business security, apex one, worry-free business security
Weakness
CWE-20
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In the news