CVE-2021-36742 — Trend Micro Multiple Products Improper Input Validation Vulnerability
2021-11-03 • CISA Known Exploited Vulnerability
[event] Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows for privilege escalation.
> AFFECTED SOFTWARE
| Field | Value |
|---|---|
| Vendor | Trend Micro |
| Product | Apex One, Apex One as a Service, and Worry-Free Business Security |
| CWE | CWE-20 |
| CVE ID | CVE-2021-36742 |
| Date Added | 2021-11-03 |
| Due Date | 2021-11-17 |
| Ransomware Campaign | Unknown |
> MITIGATION
Apply updates per vendor instructions.
Due Date: 2021-11-17