Trendmicro
Trendmicro Worry-free Business Security: vulnerabilidades y CVE
Trendmicro Worry-free Business Security tiene 58 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 4 son críticas y 5 figuran en el catálogo de explotación activa de CISA.
CVE58
Últimos 12 meses0
Críticas4
Explotadas activamente5
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2023-41179 | Alta (7.2) | 4.3% | ⚠ Explotación activa | 19 sept 2023 | A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate… |
| CVE-2020-24557 | Alta (7.8) | 2.7% | ⚠ Explotación activa | 1 sept 2020 | A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a… |
| CVE-2020-8468 | Alta (8.8) | 6.2% | ⚠ Explotación activa | 18 mar 2020 | Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent… |
| CVE-2021-36742 | Alta (7.8) | 1.5% | ⚠ Explotación activa | 29 jul 2021 | A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations.… |
| CVE-2021-36741 | Alta (8.8) | 5.0% | ⚠ Explotación activa | 29 jul 2021 | An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-49154 | Alta (7.8) | 0.12% | — | 17 jun 2025 | An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allow a local attacker to overwrite key memory-mapped files which could then have severe consequences… |
| CVE-2023-41179 | Alta (7.2) | 4.3% | ⚠ Explotación activa | 19 sept 2023 | A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate… |
| CVE-2022-36336 | Alta (7.8) | 0.57% | — | 30 jul 2022 | A link following vulnerability in the scanning function of Trend Micro Apex One and Worry-Free Business Security agents could allow a local attacker to escalate privileges on affected installations. The resolution for… |
| CVE-2022-24680 | Alta (7.8) | 0.48% | — | 24 feb 2022 | A security link following local privilege escalation vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-Free Business Security 10.0 SP1 and Trend Micro Worry-Free Business… |
| CVE-2022-24679 | Alta (7.8) | 0.48% | — | 24 feb 2022 | A security link following local privilege escalation vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-Free Business Security 10.0 SP1 and Trend Micro Worry-Free Business… |
| CVE-2022-24678 | Alta (7.5) | 2.3% | — | 24 feb 2022 | An security agent resource exhaustion denial-of-service vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-Free Business Security 10.0 SP1 and Trend Micro Worry-Free Business… |
| CVE-2022-23805 | Alta (7.1) | 0.74% | — | 4 feb 2022 | A security out-of-bounds read information disclosure vulnerability in Trend Micro Worry-Free Business Security Server could allow a local attacker to send garbage data to a specific named pipe and crash the server.… |
| CVE-2021-45442 | Alta (7.1) | 0.40% | — | 10 ene 2022 | A link following denial-of-service vulnerability in Trend Micro Worry-Free Business Security (on prem only) could allow a local attacker to overwrite arbitrary files in the context of SYSTEM. This is similar to, but not… |
| CVE-2021-45441 | Alta (7.8) | 0.27% | — | 10 ene 2022 | A origin validation error vulnerability in Trend Micro Apex One (on-prem and SaaS) could allow a local attacker drop and manipulate a specially crafted file to issue commands over a certain pipe and elevate to a higher… |
| CVE-2021-45440 | Alta (7.8) | 0.46% | — | 10 ene 2022 | A unnecessary privilege vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security 10.0 SP1 (on-prem versions only) could allow a local attacker to abuse an impersonation privilege and elevate to… |
| CVE-2021-45231 | Alta (7.8) | 0.64% | — | 10 ene 2022 | A link following privilege escalation vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to create a specially… |
| CVE-2021-44024 | Alta (7.1) | 0.40% | — | 10 ene 2022 | A link following denial-of-service vulnerability in Trend Micro Apex One (on-prem and SaaS) and Trend Micro Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to overwrite arbitrary files… |
| CVE-2021-44021 | Alta (7.8) | 0.35% | — | 3 dic 2021 | An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the… |
| CVE-2021-44020 | Alta (7.8) | 0.35% | — | 3 dic 2021 | An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the… |
| CVE-2021-44019 | Alta (7.8) | 0.35% | — | 3 dic 2021 | An unnecessary privilege vulnerability in Trend Micro Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the… |
| CVE-2021-42108 | Alta (7.8) | 0.41% | — | 21 oct 2021 | Unnecessary privilege vulnerabilities in the Web Console of Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected… |
| CVE-2021-42107 | Alta (7.8) | 0.38% | — | 21 oct 2021 | Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges… |
| CVE-2021-42106 | Alta (7.8) | 0.38% | — | 21 oct 2021 | Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges… |
| CVE-2021-42105 | Alta (7.8) | 0.38% | — | 21 oct 2021 | Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges… |
| CVE-2021-42104 | Alta (7.8) | 0.38% | — | 21 oct 2021 | Unnecessary privilege vulnerabilities in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services could allow a local attacker to escalate privileges… |
| CVE-2021-42012 | Alta (7.8) | 0.58% | — | 21 oct 2021 | A stack-based buffer overflow vulnerability in Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security 10.0 SP1 could allow a local attacker to escalate privileges on affected installations. Please… |
| CVE-2021-23139 | Alta (7.5) | 1.1% | — | 21 oct 2021 | A null pointer vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 could allow an attacker to crash the CGI program on affected installations. |
| CVE-2021-3848 | Media (5.5) | 0.23% | — | 6 oct 2021 | An arbitrary file creation by privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service, Worry-Free Business Security 10.0 SP1, and Worry-Free Business Security Services could allow a local… |
| CVE-2021-36742 | Alta (7.8) | 1.5% | ⚠ Explotación activa | 29 jul 2021 | A improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG and Worry-Free Business Security 10.0 SP1 allows a local attacker to escalate privileges on affected installations.… |
| CVE-2021-36741 | Alta (8.8) | 5.0% | ⚠ Explotación activa | 29 jul 2021 | An improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security 10.0 SP1 allows a remote attached to upload arbitrary files on affected… |
| CVE-2021-32463 | Alta (7.8) | 0.36% | — | 20 jul 2021 | An incorrect permission assignment denial-of-service vulnerability in Trend Micro Apex One, Apex One as a Service (SaaS), Worry-Free Business Security 10.0 SP1 and Worry-Free Servgices could allow a local attacker to… |
| CVE-2021-25252 | Media (5.5) | 0.62% | — | 3 mar 2021 | Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a… |
| CVE-2021-25249 | Alta (7.8) | 0.43% | — | 4 feb 2021 | An out-of-bounds write information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow a local attacker to… |
| CVE-2021-25248 | Media (5.5) | 0.89% | — | 4 feb 2021 | An out-of-bounds read information disclosure vulnerability in Trend Micro Apex One (on-prem and SaaS), OfficeScan XG SP1, and Worry-Free Business Security (10.0 SP1 and Services) could allow an attacker to disclose… |
| CVE-2021-25246 | Media (6.5) | 1.7% | — | 4 feb 2021 | An improper access control information disclosure vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG SP1, and Worry-Free Business Security could allow an unauthenticated user to create a bogus… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.