CVE-2021-36741

HIGH(8.8)KEV

Trend Micro Multiple Products Improper Input Validation Vulnerability

Description

CVE-2021-36741 is a high-severity improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security that allows a remote authenticated attacker to upload arbitrary files to affected installations. An attacker must first obtain the ability to log on to the product's management console in order to exploit this vulnerability, which is classified as an unrestricted file upload weakness (CWE-434). CISA has confirmed active exploitation by listing this vulnerability in its Known Exploited Vulnerabilities (KEV) catalog. The EPSS score of 0.58% (68.7th percentile) indicates a moderate but measurable probability of exploitation.

KEV Information

Vendor
Trend Micro
Product
Apex One, Apex One as a Service, and Worry-Free Business Security
Date Added
November 3, 2021
Due Date
November 17, 2021
Required Action
Apply updates per vendor instructions.

CVSS Score

Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in Calculator
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
LOW
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
2.8
Impact Score
5.9

CWEs

Affected Products

VendorProductVersion
trendmicroofficescanxg
trendmicroofficescan business security10.0
trendmicroapex one2019
trendmicroworry-free business security10.0

Multiple CVSS Assessments

Source: [email protected](Primary)
8.8
HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0(Secondary)
8.8
HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

References

Weakness Type

CWE-434: Unrestricted Upload of File with Dangerous Type

Unrestricted Upload of File with Dangerous Type occurs when a product allows the upload of files without sufficiently validating the file type, content, or destination. In the context of CVE-2021-36741, the Trend Micro product management console fails to properly validate file uploads, allowing an authenticated attacker to upload arbitrary files that could lead to remote code execution or other malicious activities on the server.

Learn more: CWE-434 — Unrestricted Upload of File with Dangerous Type

Impact Analysis

CVE-2021-36741 carries a CVSS 3.1 score of 8.8 (HIGH), representing a significant threat to organizations running affected Trend Micro products. The vulnerability is remotely exploitable over the network with low attack complexity, requires only low-level authentication (management console access), and no user interaction. Successful exploitation compromises confidentiality, integrity, and availability at the highest level, as arbitrary file uploads could enable remote code execution, data exfiltration, or complete system takeover. The scope remains unchanged, meaning the impact is contained to the vulnerable component, but given that the affected component is an endpoint security management server, a compromise could cascade into loss of visibility and control over all managed endpoints.

Exploit Maturity

CISA has confirmed active exploitation of CVE-2021-36741 by including it in the Known Exploited Vulnerabilities catalog, with a remediation deadline of 2021-11-17. The EPSS score of 0.58% (68.7th percentile) places it in the moderate exploitation probability range, though the confirmed KEV listing indicates that real-world attacks have already occurred. While no specific public exploit code or proof-of-concept was identified in the tracked references, the confirmed active exploitation demonstrates that threat actors have successfully weaponized this arbitrary file upload vulnerability.

Remediation

  1. Apply vendor patches immediately as required by the CISA KEV directive: Apply updates per vendor instructions. Trend Micro has released security patches addressing this vulnerability through their advisory portal.
  2. Update all affected products to their latest patched versions: Trend Micro Apex One (2019), OfficeScan XG, OfficeScan Business Security 10.0, and Worry-Free Business Security 10.0. Confirm patch status across all management server instances.
  3. Restrict access to the Trend Micro management console to authorized administrators only, using network-level access controls, VPN requirements, and multi-factor authentication to reduce the attack surface.
  4. Implement file upload monitoring and validation controls on management server systems, and review server logs for evidence of unauthorized file uploads, unusual file creation in web-accessible directories, or unexpected process execution.
  5. Conduct a thorough security review of management server file systems to identify any unauthorized files that may have been uploaded prior to patching, and scan for web shells or other persistence mechanisms.

Technical Details

CVE-2021-36741 is classified under CWE-434 (Unrestricted Upload of File with Dangerous Type) and affects the management console components of Trend Micro Apex One (2019), OfficeScan XG, OfficeScan Business Security 10.0, and Worry-Free Business Security 10.0 SP1. The vulnerability allows an authenticated attacker with management console access to bypass file upload restrictions and upload arbitrary files to the server, which could include executable content or web shells for establishing persistent access. The CVSS vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) confirms that the attack is network-based with low complexity, requires only low-level authentication (console access), and results in complete compromise of confidentiality, integrity, and availability. The requirement for prior authentication to the management console limits the attack surface somewhat, but credential theft, brute force, or exploitation of other vulnerabilities could provide the necessary access.

Frequently Asked Questions

Is CVE-2021-36741 being actively exploited?

Yes. CVE-2021-36741 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The EPSS score of 0.58% (68.7th percentile) indicates a moderate exploitation probability. There is no known association with ransomware campaigns at this time.

What products are affected by CVE-2021-36741?

CVE-2021-36741 affects Trend Micro Apex One (2019), Trend Micro OfficeScan XG, Trend Micro OfficeScan Business Security 10.0, and Trend Micro Worry-Free Business Security 10.0. The vulnerability exists in the management console component of these products.

How do I fix CVE-2021-36741?

Apply the vendor-provided patches immediately as directed by Trend Micro's security advisories. Update all management server instances to the latest patched versions. Additionally, restrict management console access to authorized administrators only and implement multi-factor authentication.

How severe is CVE-2021-36741?

CVE-2021-36741 has a CVSS 3.1 score of 8.8 (HIGH). The vulnerability allows authenticated remote attackers to upload arbitrary files, potentially leading to remote code execution. The high impact across confidentiality, integrity, and availability makes this a serious threat requiring prompt remediation.

CVSS Score

8.8
HIGH(8.8)

EPSS Score

EPSS Score4.95%
EPSS Percentile91.5%

Dates

PublishedJuly 29, 2021
Last ModifiedJune 17, 2026
StatusAnalyzed
CVSS Versionv3.1

Need Help With Vulnerability Management?

Our security experts can help you prioritize and remediate vulnerabilities effectively.