Vulnerabilities in Trend Micro

315 results
Vexday analysis

Com 9 CVEs confirmadas em exploração ativa no catálogo CISA KEV, a Trend Micro apresenta uma taxa de exploração 6,4 vezes acima da média geral do catálogo, o que indica que vulnerabilidades nessa tecnologia têm historicamente atraído atenção real de agentes maliciosos, não apenas teórica. Das 315 CVEs catalogadas, 28 possuem prova de conceito pública, ampliando a superfície de risco para equipes que operam versões desatualizadas. O maior EPSS observado chega a 0,8966, sinalizando que ao menos uma vulnerabilidade tem altíssima probabilidade estimada de exploração. A CVE mais perigosa em atividade apontada pelos dados é a CVE-2019-18187, com EPSS de 0,2513, sendo classificada como CWE-125 (leitura fora dos limites) o tipo de falha mais recorrente no portfólio, o que sugere atenção especial a controles de integridade de memória na priorização de correções.

CVE-2022-28394EOL Product CVE - Installer of Trend Micro Password Manager (Consumer) versions 3.7.0.1223 and below provided by Trend Micro Incorporated coEPSS 0.3%CVE-2021-28649An incorrect permission vulnerability in the product installer for Trend Micro HouseCall for Home Networks version 5.3.1179 and below could EPSS 0.3%CVE-2022-37348Trend Micro Security 2021 and 2022 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure Vulnerability that could allow aEPSS 0.2%CVE-2022-37347MEDIUMTrend Micro Security 2021 and 2022 (Consumer) is vulnerable to an Out-Of-Bounds Read Information Disclosure Vulnerability that could allow aEPSS 0.2%CVE-2021-44022A reachable assertion vulnerability in Trend Micro Apex One could allow an attacker to crash the program on affected installations, leading EPSS 0.2%CVE-2022-41747An improper certification validation vulnerability in Trend Micro Apex One agents could allow a local attacker to load a DLL file with systeEPSS 0.2%CVE-2021-3848An arbitrary file creation by privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service, Worry-Free Business SecuritEPSS 0.2%CVE-2022-38764A vulnerability on Trend Micro HouseCall version 1.62.1.1133 and below could allow a local attacker to escalate privlieges due to an overly EPSS 0.2%CVE-2021-43772Trend Micro Security 2021 v17.0 (Consumer) contains a vulnerability that allows files inside the protected folder to be modified without anyEPSS 0.2%CVE-2022-40710A link following vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local attacEPSS 0.2%CVE-2022-41749An origin validation error vulnerability in Trend Micro Apex One agents could allow a local attacker to escalate privileges on affected instEPSS 0.2%CVE-2022-41744A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One Vulnerability Protection integrated component could allow a local attaEPSS 0.2%CVE-2022-40707An Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local EPSS 0.2%CVE-2022-40708LOWAn Out-of-bounds read vulnerability in Trend Micro Deep Security 20 and Cloud One - Workload Security Agent for Windows could allow a local EPSS 0.2%CVE-2022-41748A registry permissions vulnerability in the Trend Micro Apex One Data Loss Prevention (DLP) module could allow a local attacker with adminisEPSS 0.2%