#VU55409 Buffer overflow in Apex One - CVE-2021-36742

 

#VU55409 Buffer overflow in Apex One - CVE-2021-36742

Published: July 28, 2021


Vulnerability identifier: #VU55409
Vulnerability risk: High
CVSSv4.0: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:A/U:Amber
CVE-ID: CVE-2021-36742
CWE-ID: CWE-119
Exploitation vector: Local access
Exploit availability: The vulnerability is being exploited in the wild
Vulnerable software:
Apex One
Software vendor:
Trend Micro

Description

The vulnerability allows a local user to escalate privileges on the system.

The vulnerability exists due to a boundary error. A local user can run a specially crafted program to trigger memory corruption and execute arability code with elevated privileges.

Note, the vulnerability is being actively exploited in the wild.


Remediation

Install updates from vendor's website.

External links