CVE-2021-36741
Trend Micro Multiple Products Improper Input Validation Vulnerability
Description
CVE-2021-36741 is a high-severity improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, OfficeScan XG, and Worry-Free Business Security that allows a remote authenticated attacker to upload arbitrary files to affected installations. An attacker must first obtain the ability to log on to the product's management console in order to exploit this vulnerability, which is classified as an unrestricted file upload weakness (CWE-434). CISA has confirmed active exploitation by listing this vulnerability in its Known Exploited Vulnerabilities (KEV) catalog. The EPSS score of 0.58% (68.7th percentile) indicates a moderate but measurable probability of exploitation.
KEV Information
CVSS Score
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:HOpen in CalculatorAffected Products
| Vendor | Product | Version |
|---|---|---|
| trendmicro | officescan | xg |
| trendmicro | officescan business security | 10.0 |
| trendmicro | apex one | 2019 |
| trendmicro | worry-free business security | 10.0 |
Multiple CVSS Assessments
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
References
- https://success.trendmicro.com/jp/solution/000287796(Broken Link, Vendor Advisory)
- https://success.trendmicro.com/jp/solution/000287815(Broken Link, Vendor Advisory)
- https://success.trendmicro.com/solution/000287819(Broken Link, Vendor Advisory)
- https://success.trendmicro.com/solution/000287820(Broken Link, Vendor Advisory)
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-36741(US Government Resource)
Weakness Type
CWE-434: Unrestricted Upload of File with Dangerous Type
Unrestricted Upload of File with Dangerous Type occurs when a product allows the upload of files without sufficiently validating the file type, content, or destination. In the context of CVE-2021-36741, the Trend Micro product management console fails to properly validate file uploads, allowing an authenticated attacker to upload arbitrary files that could lead to remote code execution or other malicious activities on the server.
Learn more: CWE-434 — Unrestricted Upload of File with Dangerous Type
Impact Analysis
CVE-2021-36741 carries a CVSS 3.1 score of 8.8 (HIGH), representing a significant threat to organizations running affected Trend Micro products. The vulnerability is remotely exploitable over the network with low attack complexity, requires only low-level authentication (management console access), and no user interaction. Successful exploitation compromises confidentiality, integrity, and availability at the highest level, as arbitrary file uploads could enable remote code execution, data exfiltration, or complete system takeover. The scope remains unchanged, meaning the impact is contained to the vulnerable component, but given that the affected component is an endpoint security management server, a compromise could cascade into loss of visibility and control over all managed endpoints.
Exploit Maturity
CISA has confirmed active exploitation of CVE-2021-36741 by including it in the Known Exploited Vulnerabilities catalog, with a remediation deadline of 2021-11-17. The EPSS score of 0.58% (68.7th percentile) places it in the moderate exploitation probability range, though the confirmed KEV listing indicates that real-world attacks have already occurred. While no specific public exploit code or proof-of-concept was identified in the tracked references, the confirmed active exploitation demonstrates that threat actors have successfully weaponized this arbitrary file upload vulnerability.
Remediation
- Apply vendor patches immediately as required by the CISA KEV directive: Apply updates per vendor instructions. Trend Micro has released security patches addressing this vulnerability through their advisory portal.
- Update all affected products to their latest patched versions: Trend Micro Apex One (2019), OfficeScan XG, OfficeScan Business Security 10.0, and Worry-Free Business Security 10.0. Confirm patch status across all management server instances.
- Restrict access to the Trend Micro management console to authorized administrators only, using network-level access controls, VPN requirements, and multi-factor authentication to reduce the attack surface.
- Implement file upload monitoring and validation controls on management server systems, and review server logs for evidence of unauthorized file uploads, unusual file creation in web-accessible directories, or unexpected process execution.
- Conduct a thorough security review of management server file systems to identify any unauthorized files that may have been uploaded prior to patching, and scan for web shells or other persistence mechanisms.
Technical Details
CVE-2021-36741 is classified under CWE-434 (Unrestricted Upload of File with Dangerous Type) and affects the management console components of Trend Micro Apex One (2019), OfficeScan XG, OfficeScan Business Security 10.0, and Worry-Free Business Security 10.0 SP1. The vulnerability allows an authenticated attacker with management console access to bypass file upload restrictions and upload arbitrary files to the server, which could include executable content or web shells for establishing persistent access. The CVSS vector (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H) confirms that the attack is network-based with low complexity, requires only low-level authentication (console access), and results in complete compromise of confidentiality, integrity, and availability. The requirement for prior authentication to the management console limits the attack surface somewhat, but credential theft, brute force, or exploitation of other vulnerabilities could provide the necessary access.
Frequently Asked Questions
Is CVE-2021-36741 being actively exploited?
Yes. CVE-2021-36741 is listed in the CISA Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. The EPSS score of 0.58% (68.7th percentile) indicates a moderate exploitation probability. There is no known association with ransomware campaigns at this time.
What products are affected by CVE-2021-36741?
CVE-2021-36741 affects Trend Micro Apex One (2019), Trend Micro OfficeScan XG, Trend Micro OfficeScan Business Security 10.0, and Trend Micro Worry-Free Business Security 10.0. The vulnerability exists in the management console component of these products.
How do I fix CVE-2021-36741?
Apply the vendor-provided patches immediately as directed by Trend Micro's security advisories. Update all management server instances to the latest patched versions. Additionally, restrict management console access to authorized administrators only and implement multi-factor authentication.
How severe is CVE-2021-36741?
CVE-2021-36741 has a CVSS 3.1 score of 8.8 (HIGH). The vulnerability allows authenticated remote attackers to upload arbitrary files, potentially leading to remote code execution. The high impact across confidentiality, integrity, and availability makes this a serious threat requiring prompt remediation.
Need Help With Vulnerability Management?
Our security experts can help you prioritize and remediate vulnerabilities effectively.