CVSS3
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
AI Score
Confidence
High
EPSS
Percentile
13.3%
An issue in the Trend Micro Apex One agent could allow an attacker who has previously acquired administrative rights via other means to bypass the protection by using a specifically crafted DLL during a specific update process.
Please note: an attacker must first obtain administrative access on the target system via another method in order to exploit this.
Vendor | Product | Version | CPE |
---|---|---|---|
trendmicro | apex_one | * | cpe:2.3:a:trendmicro:apex_one:*:*:*:*:saas:*:*:* |
trendmicro | apex_one | 2019 | cpe:2.3:a:trendmicro:apex_one:2019:-:*:*:*:*:*:* |
microsoft | windows | - | cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
[
{
"vendor": "Trend Micro, Inc.",
"product": "Trend Micro Apex One",
"versions": [
{
"version": "2019 (14.0)",
"status": "affected",
"versionType": "semver",
"lessThan": "14.0.0.11564"
}
]
}
]