Link following in Apex One - CVE-2021-45231

 

Link following in Apex One - CVE-2021-45231

Published: December 29, 2021 / Updated: January 6, 2022


Vulnerability identifier: #VU59108
CSH Severity: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2021-45231
CWE-ID: CWE-59
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
Apex One
Software vendor:
Trend Micro

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to insecure link following. A local user can create a specially crafted symbolic link and overwrite arbitrary files with arbitrary content. Successful exploitation of the vulnerability may result in execution of arbitrary code with elevated privileges.


Remediation

Install updates from vendor's website.

External links