Vulnerabilities in Trend Micro

315 results
Vexday analysis

Com 9 CVEs confirmadas em exploração ativa no catálogo CISA KEV, a Trend Micro apresenta uma taxa de exploração 6,4 vezes acima da média geral do catálogo, o que indica que vulnerabilidades nessa tecnologia têm historicamente atraído atenção real de agentes maliciosos, não apenas teórica. Das 315 CVEs catalogadas, 28 possuem prova de conceito pública, ampliando a superfície de risco para equipes que operam versões desatualizadas. O maior EPSS observado chega a 0,8966, sinalizando que ao menos uma vulnerabilidade tem altíssima probabilidade estimada de exploração. A CVE mais perigosa em atividade apontada pelos dados é a CVE-2019-18187, com EPSS de 0,2513, sendo classificada como CWE-125 (leitura fora dos limites) o tipo de falha mais recorrente no portfólio, o que sugere atenção especial a controles de integridade de memória na priorização de correções.

CVE-2017-14090A vulnerability in Trend Micro ScanMail for Exchange 12.0 exists in which some communications to the update servers are not encrypted.EPSS 1.3%CVE-2020-25777Trend Micro Antivirus for Mac 2020 (Consumer) is vulnerable to a specific kernel extension request attack where an attacker could bypass theEPSS 1.3%CVE-2018-6222Arbitrary logs location in Trend Micro Email Encryption Gateway 5.5 could allow an attacker to change location of log files and be manipulatEPSS 1.3%CVE-2019-15627Versions 10.0, 11.0 and 12.0 of the Trend Micro Deep Security Agent are vulnerable to an arbitrary file delete attack, which may lead to avaEPSS 1.3%CVE-2019-9488Trend Micro Deep Security Manager (10.x, 11.x) and Vulnerability Protection (2.0) are vulnerable to a XML External Entity Attack. However, fEPSS 1.2%CVE-2020-15603An invalid memory read vulnerability in a Trend Micro Secuity 2020 (v16.0.0.1302 and below) consumer family of products' driver could allow EPSS 1.2%CVE-2019-14686A DLL hijacking vulnerability exists in the Trend Micro Security's 2019 consumer family of products (v15) Folder Shield component and the stEPSS 1.2%CVE-2022-27883A link following vulnerability in Trend Micro Antivirus for Mac 11.5 could allow an attacker to create a specially-crafted file as a symlinkEPSS 1.2%CVE-2019-19691A vulnerability in Trend Micro Apex One and OfficeScan XG could allow an attacker to expose a masked credential key by manipulating page eleEPSS 1.2%CVE-2018-10509A vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a attacker to exploit it via a Browser Refresh attack on vulnerable inEPSS 1.1%CVE-2020-8461A CSRF protection bypass vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to get a victEPSS 1.1%CVE-2020-8462A cross-site scripting (XSS) vulnerability in Trend Micro InterScan Web Security Virtual Appliance 6.5 SP2 could allow an attacker to tamperEPSS 1.1%CVE-2022-40141A vulnerability in Trend Micro Apex One and Apex One as a Service could allow an attacker to intercept and decode certain communication striEPSS 1.1%CVE-2018-10512A vulnerability in Trend Micro Control Manager (versions 6.0 and 7.0) could allow an attacker to manipulate a reverse proxy .dll on vulnerabEPSS 1.1%CVE-2021-31517Trend Micro Home Network Security 6.5.599 and earlier is vulnerable to a file-parsing vulnerability which could allow an attacker to exploitEPSS 1.1%CVE-2021-31518Trend Micro Home Network Security 6.5.599 and earlier is vulnerable to a file-parsing vulnerability which could allow an attacker to exploitEPSS 1.1%CVE-2018-10506A out-of-bounds read information disclosure vulnerability in Trend Micro OfficeScan 11.0 SP1 and XG could allow a local attacker to discloseEPSS 1.1%CVE-2021-23139A null pointer vulnerability in Trend Micro Apex One and Worry-Free Business Security 10.0 SP1 could allow an attacker to crash the CGI progEPSS 1.1%CVE-2022-40980A potential unathenticated file deletion vulnerabilty on Trend Micro Mobile Security for Enterprise 9.8 SP5 could allow an attacker with accEPSS 1.1%CVE-2017-14093The Log Query and Quarantine Query pages in Trend Micro ScanMail for Exchange 12.0 are vulnerable to cross site scripting (XSS) attacks.EPSS 1.0%