Trendmicro
Trendmicro Officescan: vulnerabilidades y CVE
Trendmicro Officescan tiene 71 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 8 son críticas y 6 figuran en el catálogo de explotación activa de CISA.
CVE71
Últimos 12 meses0
Críticas8
Explotadas activamente6
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2019-18187 | Alta (7.5) | 25% | ⚠ Explotación activa | 28 oct 2019 | Trend Micro OfficeScan versions 11.0 and XG (12.0) could be exploited by an attacker utilizing a directory traversal vulnerability to extract files from an arbitrary zip file to a specific folder on the OfficeScan… |
| CVE-2020-8468 | Alta (8.8) | 6.2% | ⚠ Explotación activa | 18 mar 2020 | Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent… |
| CVE-2020-8467 | Alta (8.8) | 11% | ⚠ Explotación activa | 18 mar 2020 | A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute arbitrary code on affected installations (RCE). An attempted attack… |
| CVE-2020-8599 | Crítica (9.8) | 12% | ⚠ Explotación activa | 18 mar 2020 | Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected installations and bypass ROOT login.… |
| CVE-2021-36742 | Alta (7.8) | 1.5% | ⚠ Explotación activa | 29 jul 2021 | A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations.… |
| CVE-2021-36741 | Alta (8.8) | 5.0% | ⚠ Explotación activa | 29 jul 2021 | An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-32465 | Alta (8.8) | 4.3% | — | 4 ago 2021 | An incorrect permission preservation vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a remote user to perform an attack and bypass authentication on affected installations.… |
| CVE-2021-32464 | Alta (7.8) | 0.59% | — | 4 ago 2021 | An incorrect permission assignment privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security Services could allow an attacker to modify a specific script before… |
| CVE-2021-36742 | Alta (7.8) | 1.5% | ⚠ Explotación activa | 29 jul 2021 | A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations.… |
| CVE-2021-36741 | Alta (8.8) | 5.0% | ⚠ Explotación activa | 29 jul 2021 | An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected… |
| CVE-2021-28646 | Media (5.5) | 0.42% | — | 13 abr 2021 | An insecure file permissions vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a local attacker to take control of a specific log file on affected installations. |
| CVE-2021-28645 | Alta (7.8) | 0.51% | — | 13 abr 2021 | An incorrect permission assignment vulnerability in Trend Micro Apex One, Apex One as a Service and OfficeScan XG SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an… |
| CVE-2021-25253 | Alta (7.8) | 1.9% | — | 13 abr 2021 | An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a resource used by the service could allow a local attacker to escalate privileges on affected… |
| CVE-2021-25250 | Alta (7.8) | 0.51% | — | 13 abr 2021 | An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a sensitive file could allow a local attacker to escalate privileges on affected… |
| CVE-2021-25252 | Media (5.5) | 0.62% | — | 3 mar 2021 | Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a… |
| CVE-2021-25249 | Alta (7.8) | 0.43% | — | 4 feb 2021 | An out-of-bounds write information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to… |
| CVE-2021-25248 | Media (5.5) | 0.89% | — | 4 feb 2021 | An out-of-bounds read information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow an attacker to disclose… |
| CVE-2021-25246 | Media (6.5) | 1.7% | — | 4 feb 2021 | An improper access control information disclosure vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG SP1, and Worry-Free Business Security could allow an unauthenticated user to create a bogus… |
| CVE-2021-25243 | Media (5.3) | 2.2% | — | 4 feb 2021 | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain patch level information. |
| CVE-2021-25242 | Media (5.3) | 2.2% | — | 4 feb 2021 | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain version and build… |
| CVE-2021-25240 | Media (5.3) | 2.1% | — | 4 feb 2021 | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain x64 agent hofitx… |
| CVE-2021-25239 | Media (5.3) | 2.1% | — | 4 feb 2021 | An improper access control vulnerability in Trend Micro Apex One (on-prem), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about x86 agent hotfixes. |
| CVE-2021-25238 | Media (5.3) | 2.1% | — | 4 feb 2021 | An improper access control information disclosure vulnerability in Trend Micro OfficeScan XG SP1 and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about an agent's… |
| CVE-2021-25236 | Media (5.3) | 1.9% | — | 4 feb 2021 | A server-side request forgery (SSRF) information disclosure vulnerability in Trend Micro OfficeScan XG SP1 and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to locate online agents via a… |
| CVE-2021-25235 | Media (5.3) | 2.1% | — | 4 feb 2021 | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about a content inspection configuration file. |
| CVE-2021-25234 | Media (5.3) | 2.1% | — | 4 feb 2021 | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about a… |
| CVE-2021-25233 | Media (5.3) | 2.1% | — | 4 feb 2021 | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about a… |
| CVE-2021-25232 | Media (5.3) | 2.0% | — | 4 feb 2021 | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about the SQL database. |
| CVE-2021-25231 | Media (5.3) | 2.2% | — | 4 feb 2021 | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about a… |
| CVE-2021-25230 | Media (5.3) | 2.1% | — | 4 feb 2021 | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about the contents of a scan connection exception file. |
| CVE-2021-25229 | Media (5.3) | 2.1% | — | 4 feb 2021 | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS) and OfficeScan XG SP1 could allow an unauthenticated user to obtain information about the database server. |
| CVE-2021-25228 | Media (5.3) | 2.1% | — | 4 feb 2021 | An improper access control vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security 10.0 SP1 could allow an unauthenticated user to obtain information about hotfix… |
| CVE-2020-28583 | Media (5.3) | 3.2% | — | 1 dic 2020 | An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal version, build and patch… |
| CVE-2020-28582 | Media (5.3) | 3.2% | — | 1 dic 2020 | An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal number of managed agents. |
| CVE-2020-28577 | Media (5.3) | 3.2% | — | 1 dic 2020 | An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal server hostname and db names. |
| CVE-2020-28576 | Media (5.3) | 3.2% | — | 1 dic 2020 | An improper access control information disclosure vulnerability in Trend Micro Apex One and OfficeScan XG SP1 could allow an unauthenticated user to connect to the product server and reveal version and build information. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Trendmicro
Apex ONE · 180Worry-free Business Security · 58Apex Central · 35Interscan WEB Security Virtual Appliance · 29Worry-free Business Security Services · 25Control Manager · 22Mobile Security · 21Email Encryption Gateway · 19Serverprotect · 18Internet Security · 17Password Manager · 15Deep Security Agent · 15