← Back

Trendmicro

trendmicro

559 CVEs • 105 products

Products (105)

Click to collapse
Toggle
Apex One
apex_one
Officescan
officescan
Apex Central
apex_central
Antivirus+
antivirus+
Serverprotect
serverprotect
Housecall
housecall
Security
security
Deep Security
deep_security
Scanmail
scanmail
Officescan Xg
officescan_xg
Dr. Safety
dr._safety
Im Security
im_security
Safe Lock
safe_lock
Cloud Edge
cloud_edge
Antivirus One
antivirus_one
Tmeext.sys
tmeext.sys
Ransom Buster
ransom_buster
Online Scan
online_scan
Rootkit Buster
rootkit_buster
Portal Protect
portal_protect

CVEs (559)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Trendmicro
12Antivirus Toolkit
Apex OneDeep Security+9 more
Nov 21, 2024
Aug 5, 2020
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver could allow an attacker in user-mode with administrator permissions to abuse...Show more
An input validation vulnerability found in multiple Trend Micro products utilizing a particular version of a specific rootkit protection driver could allow an attacker in user-mode with administrator permissions to abuse the driver to modify a kernel address that may cause a system crash or potentially lead to code execution in kernel mode. An attacker must already have obtained administrator access on the target machine (either legitimately or via a separate unrelated attack) to exploit this vulnerability.Show less
1Trendmicro
4Antivirus+ 2020
Internet Security 2020Maximum Security 2020+1 more
Nov 21, 2024
Jul 15, 2020
N/A· v4
7.5 HIGH· v3
7.8 HIGH· v2
An invalid memory read vulnerability in a Trend Micro Secuity 2020 (v16.0.0.1302 and below) consumer family of products' driver could allow an attacker to manipulate the specific driver to do a system call operation with...Show more
An invalid memory read vulnerability in a Trend Micro Secuity 2020 (v16.0.0.1302 and below) consumer family of products' driver could allow an attacker to manipulate the specific driver to do a system call operation with an invalid address, resulting in a potential system crash.Show less
1Trendmicro
4Antivirus+ 2020
Internet Security 2020Maximum Security 2020+1 more
Nov 21, 2024
Jul 15, 2020
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
An untrusted search path remote code execution (RCE) vulnerability in the Trend Micro Secuity 2020 (v16.0.0.1146 and below) consumer family of products could allow an attacker to run arbitrary code on a vulnerable system...Show more
An untrusted search path remote code execution (RCE) vulnerability in the Trend Micro Secuity 2020 (v16.0.0.1146 and below) consumer family of products could allow an attacker to run arbitrary code on a vulnerable system. As the Trend Micro installer tries to load DLL files from its current directory, an arbitrary DLL could also be loaded with the same privileges as the installer if run as Administrator. User interaction is required to exploit the vulnerbaility in that the target must open a malicious directory or device.Show less
1Trendmicro
1Interscan Web Security Virtual Appliance
Nov 21, 2024
May 27, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to bypass authentication on affected installations of Trend Micro InterScan Web Security Virtual Appliance.
1Trendmicro
1Interscan Web Security Virtual Appliance
Nov 21, 2024
May 27, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to execute arbitrary code on affected installations. Authentication is required to exploit this vulnerability.
1Trendmicro
1Interscan Web Security Virtual Appliance
Nov 21, 2024
May 27, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow remote attackers to disclose sensitive informatoin on affected installations.
1Trendmicro
1Interscan Web Security Virtual Appliance
Nov 21, 2024
May 27, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
A cross-site scripting vulnerability (XSS) in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow a remote attacker to tamper with the web interface of affected installations. User interaction is required...Show more
A cross-site scripting vulnerability (XSS) in Trend Micro InterScan Web Security Virtual Appliance 6.5 may allow a remote attacker to tamper with the web interface of affected installations. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.Show less
1Trendmicro
1Worry Free Business Security
Nov 21, 2024
Mar 18, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Trend Micro Worry-Free Business Security (9.0, 9.5, 10.0) is affected by a directory traversal vulnerability that could allow an attacker to manipulate a key file to bypass authentication.
1Trendmicro
2Apex One
Officescan
Oct 31, 2025
Mar 18, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected installations and bypass ROOT login. Authenti...Show more
Trend Micro Apex One (2019) and OfficeScan XG server contain a vulnerable EXE file that could allow a remote attacker to write arbitrary data to an arbitrary path on affected installations and bypass ROOT login. Authentication is not required to exploit this vulnerability.Show less
1Trendmicro
3Apex One
OfficescanWorry Free Business Security
Nov 21, 2024
Mar 18, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow a remote attacker to execute arbitrary code on affected installa...Show more
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow a remote attacker to execute arbitrary code on affected installations with SYSTEM level privileges. Authentication is not required to exploit this vulnerability.Show less
1Trendmicro
3Apex One
OfficescanWorry Free Business Security
Nov 21, 2024
Mar 18, 2020
N/A· v4
7.5 HIGH· v3
9.4 HIGH· v2
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow an attacker to delete any file on the server with SYSTEM level p...Show more
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) server contains a vulnerable service DLL file that could allow an attacker to delete any file on the server with SYSTEM level privileges. Authentication is not required to exploit this vulnerability.Show less
1Trendmicro
3Apex One
OfficescanWorry Free Business Security
Oct 31, 2025
Mar 18, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent clie...Show more
Trend Micro Apex One (2019), OfficeScan XG and Worry-Free Business Security (9.0, 9.5, 10.0) agents are affected by a content validation escape vulnerability which could allow an attacker to manipulate certain agent client components. An attempted attack requires user authentication.Show less
1Trendmicro
2Apex One
Officescan
Oct 31, 2025
Mar 18, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute arbitrary code on affected installations (RCE). An attempted attack requi...Show more
A migration tool component of Trend Micro Apex One (2019) and OfficeScan XG contains a vulnerability which could allow remote attackers to execute arbitrary code on affected installations (RCE). An attempted attack requires user authentication.Show less
1Trendmicro
1Password Manager
Nov 21, 2024
Mar 12, 2020
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
Trend Micro Password Manager for Windows version 5.0 is affected by a DLL hijacking vulnerability would could potentially allow an attacker privleged escalation.
1Trendmicro
1Vulnerability Protection
Nov 21, 2024
Feb 20, 2020
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Trend Micro Vulnerability Protection 2.0 is affected by a vulnerability that could allow an attack to use the product installer to load other DLL files located in the same directory.
1Trendmicro
5Antivirus + Security 2019
Internet Security 2019Maximum Security 2019+2 more
Nov 21, 2024
Feb 20, 2020
N/A· v4
4.7 MEDIUM· v3
1.9 LOW· v2
The Trend Micro Security 2019 (15.0.0.1163 and below) consumer family of products is vulnerable to a denial of service (DoS) attack in which a malicious actor could manipulate a key file at a certain time during the syst...Show more
The Trend Micro Security 2019 (15.0.0.1163 and below) consumer family of products is vulnerable to a denial of service (DoS) attack in which a malicious actor could manipulate a key file at a certain time during the system startup process to disable the product's malware protection functions or the entire product completely..Show less
1Trendmicro
8Control Manager
Endpoint SensorIm Security+5 more
Nov 21, 2024
Feb 20, 2020
N/A· v4
7.0 HIGH· v3
5.1 MEDIUM· v2
Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product installat...Show more
Trend Micro has repackaged installers for several Trend Micro products that were found to utilize a version of an install package that had a DLL hijack vulnerability that could be exploited during a new product installation. The vulnerability was found to ONLY be exploitable during an initial product installation by an authorized user. The attacker must convince the target to download malicious DLL locally which must be present when the installer is run.Show less
1Trendmicro
1Anti Threat Toolkit
Nov 21, 2024
Jan 30, 2020
N/A· v4
7.8 HIGH· v3
5.1 MEDIUM· v2
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution...Show more
Trend Micro Anti-Threat Toolkit (ATTK) versions 1.62.0.1218 and below have a vulnerability that may allow an attacker to place malicious files in the same directory, potentially leading to arbitrary remote code execution (RCE) when executed. Another attack vector similar to CVE-2019-9491 was idenitfied and resolved in version 1.62.0.1228 of the tool.Show less
1Trendmicro
8Antivirus + Security 2019
Antivirus + Security 2020Internet Security 2019+5 more
Nov 21, 2024
Jan 18, 2020
N/A· v4
7.8 HIGH· v3
7.2 HIGH· v2
A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious pr...Show more
A Persistent Arbitrary Code Execution vulnerability exists in the Trend Micro Security 2020 (v160 and 2019 (v15) consumer familiy of products which could potentially allow an attacker the ability to create a malicious program to escalate privileges and attain persistence on a vulnerable system.Show less
1Trendmicro
4Antivirus + Security 2019
Internet Security 2019Maximum Security 2019+1 more
Nov 21, 2024
Jan 18, 2020
N/A· v4
6.7 MEDIUM· v3
7.2 HIGH· v2
An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products which could allow an attacker to gain elevated privileges and tamper with protected services by disablin...Show more
An arbitrary code execution vulnerability exists in the Trend Micro Security 2019 (v15) consumer family of products which could allow an attacker to gain elevated privileges and tamper with protected services by disabling or otherwise preventing them to start. An attacker must already have administrator privileges on the target machine in order to exploit the vulnerability.Show less