Trend Micro warns customers of zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2020-24557 | Improper Access Control LPE in Trend Micro Apex One and Worry-Free Business Security Trend Micro Apex One, OfficeScan, and Worry-Free Business Security 10.0 SP1 on Microsoft Windows contain an improper access control flaw that lets an attacker manipulate a specific product folder to temporarily disable the security product and abuse a Windows function to escalate privileges. The attacker must first obtain the ability to execute low-privileged code on the target system; Windows 10 version 1909 (OS Build 18363.719) mitigates the hard-link technique, so earlier Windows versions are the easier targets. Successful exploitation yields local privilege escalation with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.8). Any organization running these Trend Micro endpoint agents on unpatched Windows machines is affected, with exposure driven by fleet size rather than internet-facing services. The vulnerability is being exploited in the wild per vendor advisories and news coverage, and CISA added it to the KEV catalog on 2021-11-03 with the required action of applying vendor updates; no public proof-of-concept is documented. Do: Apply Trend Micro's patched builds for Apex One and Worry-Free Business Security 10.0 SP1 per the vendor advisory, as CISA's required action directs. Prioritize hosts running Windows versions older than Windows 10 1909 (OS Build 18363.719), where the hard-link mitigation is absent, and verify no unpatched agents remain in your fleet. Also check endpoints for signs of prior low-privileged code execution and local privilege escalation, since the flaw requires an existing foothold to exploit. | 7.8 | 3% | KEV |
| largehundreds of thousands of managed Windows endpoints (order-of-magnitude estimate) | |
| CVE-2021-32465 +1 in the same advisory: …32464 | An incorrect permission preservation vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a remote user to perform an An incorrect permission preservation vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a remote user to perform an attack and bypass authentication on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. NVD description · AI analysis pending | 8.8 group max | 4% |
| — | ||
| CVE-2021-36741 +1 in the same advisory: …36742 | Authenticated Arbitrary File Upload in Trend Micro Apex One and OfficeScan Consoles CVE-2021-36741 is an improper input validation flaw (CWE-434) in the management consoles of Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 that permits the upload of arbitrary files on affected installations. It is triggered remotely over the network (CVSS AV:N) by an attacker who has first obtained logon access to the product's management console (PR:L), with no user interaction required. Successful exploitation lets the attacker place arbitrary files on the management server, with high potential impact to confidentiality, integrity, and availability (CVSS 3.1 score 8.8). Organizations running any of these Trend Micro endpoint-security consoles are affected, including tenants of the cloud-hosted Apex One as a Service. The flaw is in CISA's Known Exploited Vulnerabilities catalog (added 2021-11-03), indicating known in-the-wild exploitation; no public proof-of-concept is known, ransomware use is unconfirmed, and news reports indicate attackers attempted to exploit zero-days in the Trend Micro Apex One platform. Do: Apply Trend Micro's patches to on-premises Apex One, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 per the vendor advisories and CISA's required action, and confirm the Apex One as a Service-hosted console has been updated by Trend Micro. Because exploitation requires an authenticated console session, restrict management-console logon to trusted administrators, use strong credentials/MFA, and audit console logs for unexpected file uploads or unfamiliar sessions. Treat any internet-exposed management console as higher risk and prioritize patching it. | 8.8 group max | 5% | KEV |
| largelikely tens of thousands of management console deployments worldwide across the four products, plus all Apex One as a Service tenants (order-of-magnitude… |
Full article237 words · extracted from securityaffairs.com · click to collapse

Security firms Trend Micro is warning its customers of attacks exploiting zero-day vulnerabilities in its Apex One and Apex One as a Service products.
On July 28, Trend Micro released security patches for multiple incorrect permission assignment privilege escalation, incorrect permission preservation authentication bypass, arbitrary file upload, and local privilege escalation vulnerabilities in Apex One and Apex One as a Service products. The security firm also reported that attackers are already exploits at least two of the flaws (CVE-2021-32464, CVE-2021-32465, CVE-2021-36741, CVE-2021-36742) in attacks in the wild.
The vulnerabilities affect the Trend Micro Apex One (On Premise) and Apex One as a Service (SaaS) on Windows.
“Trend Micro has observed an active attempt of exploitation against two of these vulnerabilities (chained) in-the-wild (ITW) in a very limited number of instances, and we have been in contact with these customers already. All customers are strongly encouraged to update to the latest versions as soon as possible.” reads the advisory.
The company did not share info about the attacks in the wild that exploited the above vulnerabilities.
In April, the security firm revealed that attackers were actively exploiting a vulnerability, tracked as CVE-2020-24557, in its antivirus solutions to gain admin rights on Windows systems.
The CVE-2020-24557 vulnerability affects the Apex One and OfficeScan XG enterprise security products.
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, zero-day)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/121082/security/trend-micro-zero-day-attacks.html