An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allow a local attacker to overwrite key memory-mapped files which could then have severe consequences for the security and stability of affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
| Software | From | Fixed in |
|---|---|---|
| trendmicro / worry-free_business_security | 10.0-sp1 | 10.0-sp1.x |
| trendmicro / worry-free_business_security_services | 6.7.0.0 | 6.7.3954 |
| trendmicro / worry-free_business_security_services | 14.0.0 | 14.3.1299 |
| trendmicro / apex_one | - | 14.0.14492 |
| trendmicro / apex_one | 14.0.0.12994 | 14.0.0.14002 |