LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-36742: Trend Micro Multiple Products Improper Input Validation Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-36742 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security contain an improper input validation vulnerability that allows for privilege escalation.

CVE-2021-36742 is an improper input validation vulnerability in Trend Micro Apex One, Apex One as a Service, and Worry-Free Business Security. It can allow an attacker to escalate privileges on affected systems. For IT and security teams running these endpoint security products, this matters because privilege escalation can turn limited access into broader control of the host, increasing the impact of any initial foothold.

Public detail is limited to the products named above and the privilege-escalation outcome. Confirm exact affected builds, fixed versions, and deployment guidance against the vendor advisory before acting.

How it works

The weakness is classified as CWE-20 (Improper Input Validation). In this class of flaw, software does not adequately check or sanitize data it receives before using it in a security-sensitive operation. When that occurs in an endpoint security agent or related service that runs with elevated rights, a local attacker who can supply crafted input may cause the component to perform actions with higher privileges than the attacker originally held.

CISA summarizes the issue as an improper input validation vulnerability that allows for privilege escalation. Specifics of the input path, required access level, or exact abuse sequence are not provided in the given facts; treat any public proof-of-concept claims cautiously and validate mechanics only against the vendor advisory. The practical risk is that successful abuse elevates the attacker’s standing on the machine, which can enable further persistence, defense evasion, or lateral movement depending on the environment.

Am I affected? How to find it in your systems

These products are typically deployed as endpoint protection agents on Windows workstations and servers, and in managed or cloud-delivered forms (Apex One as a Service). Worry-Free Business Security is commonly used in smaller business environments. Inventory every host and management console that runs Trend Micro Apex One, Apex One as a Service, or Worry-Free Business Security.

How to remediate

Patch first. Apply the updates Trend Micro released for this issue, following the vendor instructions referenced by CISA’s required action. Confirm the exact packages or agent builds for Apex One, Apex One as a Service, and Worry-Free Business Security in the official advisory, then roll them out through your standard change process.

If you can't patch immediately

Until the vendor update is applied, reduce exposure with compensating controls appropriate to endpoint security agents and privilege-escalation flaws.

These steps lower risk; they do not replace the patch. Schedule the update as soon as practical.

If your data may have been exposed

Actively exploited privilege-escalation vulnerabilities can contribute to broader compromise and data exposure, though ransomware use is not documented for this CVE in the given facts. If you suspect abuse, isolate affected hosts, preserve forensic data, rotate credentials that may have been accessible, and follow your incident-response plan. You can run a free exposure scan of your email addresses against known breach data to see whether associated accounts appear in prior breaches and to prioritize further checks.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedTrend Micro · Apex One, Apex One as a Service, and Worry-Free Business Security
WeaknessCWE-20
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities