← Back

Trendmicro

trendmicro

559 CVEs • 105 products

Products (105)

Click to collapse
Toggle
Apex One
apex_one
Officescan
officescan
Apex Central
apex_central
Antivirus+
antivirus+
Serverprotect
serverprotect
Housecall
housecall
Security
security
Deep Security
deep_security
Scanmail
scanmail
Officescan Xg
officescan_xg
Dr. Safety
dr._safety
Im Security
im_security
Safe Lock
safe_lock
Cloud Edge
cloud_edge
Antivirus One
antivirus_one
Tmeext.sys
tmeext.sys
Ransom Buster
ransom_buster
Online Scan
online_scan
Rootkit Buster
rootkit_buster
Portal Protect
portal_protect

CVEs (559)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Trendmicro
4Antivirus+ 2020
Internet Security 2020Maximum Security 2020+1 more
Nov 21, 2024
Sep 29, 2020
N/A· v4
6.3 MEDIUM· v3
6.3 MEDIUM· v2
The Trend Micro Security 2020 (v16) consumer family of products is vulnerable to a security race condition arbitrary file deletion vulnerability that could allow an unprivileged user to manipulate the product's secure er...Show more
The Trend Micro Security 2020 (v16) consumer family of products is vulnerable to a security race condition arbitrary file deletion vulnerability that could allow an unprivileged user to manipulate the product's secure erase feature to delete files with a higher set of privileges.Show less
1Trendmicro
1Apex One
Nov 21, 2024
Sep 29, 2020
N/A· v4
4.3 MEDIUM· v3
4.3 MEDIUM· v2
A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to trigger an out-of-bounds red information disclosure which would disclose sensitive information to an unprivileged accou...Show more
A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to trigger an out-of-bounds red information disclosure which would disclose sensitive information to an unprivileged account. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.Show less
1Trendmicro
1Apex One
Nov 21, 2024
Sep 29, 2020
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to execute arbitrary code on affected products. User interaction is required to exploit this vulnerability in that the tar...Show more
A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to execute arbitrary code on affected products. User interaction is required to exploit this vulnerability in that the target must import a corrupted configuration file.Show less
1Trendmicro
1Apex One
Nov 21, 2024
Sep 29, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An...Show more
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute low-privileged code on the target in order to exploit these vulnerabilities. The subs affected in this vulnerability makes it unique compared to similar CVEs such as CVE-2020-24564 and CVE-2020-25771.Show less
1Trendmicro
1Apex One
Nov 21, 2024
Sep 29, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An...Show more
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute low-privileged code on the target in order to exploit these vulnerabilities. The subs affected in this vulnerability makes it unique compared to similar CVEs such as CVE-2020-24564 and CVE-2020-25770.Show less
1Trendmicro
1Apex One
Nov 21, 2024
Sep 29, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An...Show more
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute low-privileged code on the target in order to exploit these vulnerabilities. The subs affected in this vulnerability makes it unique compared to similar CVEs such as CVE-2020-24564 and CVE-2020-25771.Show less
1Trendmicro
1Apex One
Nov 21, 2024
Sep 29, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An...Show more
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute low-privileged code on the target in order to exploit these vulnerabilities. The subs affected in this vulnerability makes it unique compared to similar CVEs such as CVE-2020-24564 and CVE-2020-25770.Show less
1Trendmicro
1Apex One
Nov 21, 2024
Sep 29, 2020
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An...Show more
An out-of-bounds read information disclosure vulnerabilities in Trend Micro Apex One may allow a local attacker to disclose sensitive information to an unprivileged account on vulnerable installations of the product. An attacker must first obtain the ability to execute low-privileged code on the target in order to exploit these vulnerabilities. The subs affected in this vulnerability makes it unique compared to similar CVEs such as CVE-2020-24565 and CVE-2020-25770.Show less
1Trendmicro
1Apex One
Nov 21, 2024
Sep 29, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability in Trend Micro Apex One may allow a local attacker to manipulate the process of the security agent unload option (if configured), which then could be manipulated to gain a privilege escalation and code ex...Show more
A vulnerability in Trend Micro Apex One may allow a local attacker to manipulate the process of the security agent unload option (if configured), which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability to execute low-privileged code on the target in order to exploit this vulnerability.Show less
1Trendmicro
1Officescan
Nov 21, 2024
Sep 29, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability in Trend Micro OfficeScan XG SP1 on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code executi...Show more
A vulnerability in Trend Micro OfficeScan XG SP1 on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This CVE is similar, but not identical to CVE-2020-24556.Show less
1Trendmicro
5Antivirus+ 2019
Internet Security 2019Maximum Security 2019+2 more
Nov 21, 2024
Sep 24, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an aff...Show more
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of the expected one. CWE-295: Improper server certificate verification in the communication with the update server.Show less
1Trendmicro
5Antivirus+ 2019
Internet Security 2019Maximum Security 2019+2 more
Nov 21, 2024
Sep 24, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an aff...Show more
An incomplete SSL server certification validation vulnerability in the Trend Micro Security 2019 (v15) consumer family of products could allow an attacker to combine this vulnerability with another attack to trick an affected client into downloading a malicious update instead of the expected one. CWE-494: Update files are not properly verified.Show less
1Trendmicro
1Serverprotect
Nov 21, 2024
Sep 15, 2020
N/A· v4
9.1 CRITICAL· v3
9.0 HIGH· v2
A command injection vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow an attacker to execute arbitrary code on an affected system. An attacker must first obtain admin/root privileges on the SPLX consol...Show more
A command injection vulnerability in Trend Micro ServerProtect for Linux 3.0 could allow an attacker to execute arbitrary code on an affected system. An attacker must first obtain admin/root privileges on the SPLX console to exploit this vulnerability.Show less
1Trendmicro
4Apex One
OfficescanWorry Free Business Security+1 more
Nov 21, 2024
Sep 1, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability in Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services on macOS may allow an attacker to manipulate a certain binary to load and run a script from a user-...Show more
A vulnerability in Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services on macOS may allow an attacker to manipulate a certain binary to load and run a script from a user-writable folder, which then would allow them to execute arbitrary code as root. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.Show less
1Trendmicro
3Apex One
Worry Free Business SecurityWorry Free Business Security Services
Nov 21, 2024
Sep 1, 2020
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
A vulnerability in an Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services dll may allow an attacker to manipulate it to cause an out-of-bounds read that crashes multiple...Show more
A vulnerability in an Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services dll may allow an attacker to manipulate it to cause an out-of-bounds read that crashes multiple processes in the product. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.Show less
1Trendmicro
2Apex One
Worry Free Business Security
Oct 31, 2025
Sep 1, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific...Show more
A vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 on Microsoft Windows may allow an attacker to manipulate a particular product folder to disable the security temporarily, abuse a specific Windows function and attain privilege escalation. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Please note that version 1909 (OS Build 18363.719) of Microsoft Windows 10 mitigates hard links, but previous versions are affected.Show less
1Trendmicro
3Apex One
Worry Free Business SecurityWorry Free Business Security Services
Nov 21, 2024
Sep 1, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A vulnerability in Trend Micro Apex One, OfficeScan XG SP1, Worry-Free Business Security 10 SP1 and Worry-Free Business Security Services on Microsoft Windows may allow an attacker to create a hard link to any file on th...Show more
A vulnerability in Trend Micro Apex One, OfficeScan XG SP1, Worry-Free Business Security 10 SP1 and Worry-Free Business Security Services on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. Please note that version 1909 (OS Build 18363.719) of Microsoft Windows 10 mitigates hard links, but previous versions are affected.Show less
1Trendmicro
2Deep Security Manager
Vulnerability Protection
Nov 21, 2024
Aug 27, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A vulnerability in the management consoles of Trend Micro Deep Security 10.0-12.0 and Trend Micro Vulnerability Protection 2.0 SP2 may allow an authenticated attacker with full control privileges to bypass file integrity...Show more
A vulnerability in the management consoles of Trend Micro Deep Security 10.0-12.0 and Trend Micro Vulnerability Protection 2.0 SP2 may allow an authenticated attacker with full control privileges to bypass file integrity checks, leading to remote code execution.Show less
1Trendmicro
2Deep Security Manager
Vulnerability Protection
Nov 21, 2024
Aug 27, 2020
N/A· v4
8.1 HIGH· v3
5.1 MEDIUM· v2
If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Vulnerability Protection 2.0 SP2 could allow an unauthenticated attacker with prior knowledge of the targeted organization to...Show more
If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Vulnerability Protection 2.0 SP2 could allow an unauthenticated attacker with prior knowledge of the targeted organization to bypass manager authentication. Enabling multi-factor authentication prevents this attack. Installations using manager native authentication or SAML authentication are not impacted by this vulnerability.Show less
1Trendmicro
2Deep Security Manager
Vulnerability Protection
Nov 21, 2024
Aug 27, 2020
N/A· v4
8.1 HIGH· v3
5.1 MEDIUM· v2
If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Deep Security 10.x-12.x could allow an unauthenticated attacker with prior knowledge of the targeted organization to bypass ma...Show more
If LDAP authentication is enabled, an LDAP authentication bypass vulnerability in Trend Micro Deep Security 10.x-12.x could allow an unauthenticated attacker with prior knowledge of the targeted organization to bypass manager authentication. Enabling multi-factor authentication prevents this attack. Installations using manager native authentication or SAML authentication are not impacted by this vulnerability.Show less