Trend Micro Security (Consumer) 2021 and 2020 are vulnerable to a directory junction vulnerability which could allow an attacker to exploit the system to escalate privileges and create a denial of service.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Maximum_security_2019 | Trendmicro | 15.0 (including) | 15.0 (including) |
Maximum_security_2020 | Trendmicro | 16.0 (including) | 16.0 (including) |
Maximum_security_2021 | Trendmicro | 17.0 (including) | 17.0 (including) |
Maximum_security_2021 | Trendmicro | 17.2 (including) | 17.2 (including) |
Security_for_best_buy | Trendmicro | 2021 (including) | 2021 (including) |