LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-36741: Trend Micro Multiple Products Improper Input Validation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-36741 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows a remote attacker to upload files.

CVE-2021-36741 is an improper input validation flaw in Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security. It allows a remote attacker to upload files. Because these products are endpoint and security management platforms, successful abuse can put agent or management infrastructure at risk and warrants prompt attention from IT and security teams.

CISA lists the required action as applying updates per the vendor’s instructions. Known ransomware use is not documented for this CVE. Confirm all version, component, and fix details directly against the Trend Micro advisory before acting.

How it works

The weakness is classified as CWE-22 (improper limitation of a pathname to a restricted directory, commonly associated with path traversal and related input-validation failures). In this case the CISA summary states that improper input validation lets a remote attacker upload files.

At a high level, an attacker who can reach an exposed management or agent interface supplies crafted input that the product does not adequately validate. That input can cause the application to accept and store a file in a location or under a name the attacker influences. Exact request format, authentication requirements, and reachable endpoints are not provided in the public summary; defenders must treat any internet- or network-facing management surface of the listed products as potentially in scope and verify behavior against the vendor advisory.

Am I affected? How to find it in your systems

These products typically run as on-premises management servers, cloud-managed (Apex One as a Service) consoles, and endpoint agents deployed across Windows and other supported platforms in enterprise and SMB environments.

If you cannot confirm version status internally, open a case with Trend Micro support and reference the CVE and product names above.

How to remediate

Patch first. Apply the updates Trend Micro released for Apex One, Apex One as a Service, and Worry-Free Business Security exactly as described in the vendor advisory. CISA’s required action is to apply updates per vendor instructions.

If you can't patch immediately

Until the vendor update is installed, reduce exposure with compensating controls appropriate to a remote file-upload / improper-input-validation issue.

If your data may have been exposed

Actively exploited vulnerabilities can lead to unauthorized access and data exposure even when ransomware use is not documented for the specific CVE. If you have evidence of exploitation or cannot rule it out, follow your incident-response process: isolate affected systems, preserve logs, and assess what data or credentials may have been reachable from the compromised management or agent tier.

As a further check, you can run a free exposure scan of your email addresses against known breach data to see whether associated credentials or personal information have appeared in prior incidents, then force password resets and review access where matches are found.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedTrend Micro · Apex One, Apex One as a Service, and Worry-Free Business Security
WeaknessCWE-22
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities