CVE-2021-25252
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Exploitability: 1.8 / Impact: 3.6
Source: NVD
Description
Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file.
Affected (23)
Products: Trendmicro: Apex Central, Apex One, Cloud Edge, Deep Security, Control Manager, Deep Discovery Analyzer, Deep Discovery Email Inspector, Deep Discovery Inspector, Interscan Messaging Security Virtual Appliance, Interscan Web Security Virtual Appliance, Officescan, Portal Protect, Scanmail, Scanmail For Ibm Domino, Serverprotect For Storage, Serverprotect, Serverprotect For Network Appliance Filers, Safe Lock, Worry Free Business Security
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2019 |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2019 |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.0 |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Apple Macos | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.0 |
Configuration F
| Vulnerable Software | Affected Versions |
|---|---|
| Version 7.0 |
Configuration G
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.1 |
Configuration H
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.5 |
Configuration I
| Vulnerable Software | Affected Versions |
|---|---|
| Version 3.8 |
Configuration J
| Vulnerable Software | Affected Versions |
|---|---|
| Version 9.1 |
Configuration K
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.5 |
Configuration L
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
Configuration M
| Vulnerable Software | Affected Versions |
|---|---|
| Version 2.6 |
Configuration N
| Vulnerable Software | Affected Versions |
|---|---|
| Version 14.0 |
Configuration O
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.8 |
| Running on/with | Platform Versions |
|---|---|
Linux Linux Kernel | All versions |
Configuration P
| Vulnerable Software | Affected Versions |
|---|---|
| Version 6.0 |
Configuration Q
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.8 |
| Running on/with | Platform Versions |
|---|---|
Emc Celerra Network Attached Storage | All versions |
Novell Netware | All versions |
Configuration R
| Vulnerable Software | Affected Versions |
|---|---|
| Version 5.8 |
| Running on/with | Platform Versions |
|---|---|
Netapp Cluster Data Ontap | All versions |
Configuration S
| Vulnerable Software | Affected Versions |
|---|---|
| Version 1.1 |
Configuration T
| Vulnerable Software | Affected Versions |
|---|---|
| Version 10.1 |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows | All versions |
References (2)
Source: security@trendmicro.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Timeline
No history available yet.