Security restrictions bypass in Apex One and Worry-Free Business Security - CVE-2021-3848
Published: October 4, 2021
Vulnerability details
The vulnerability allows a local user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper privileges management in Trend Micro Apex One and Trend Micro Worry-Free Business Security. A local user can create arbitrary files on the system with higher privileges.
Successful exploitation of the vulnerability can result in denial of service conditions.
Affected software
Worry-Free Business Security
How to mitigate CVE-2021-3848
Worry-Free Business Security - update to 10 SP1 Patch 2342