CVE-2021-25252

Description

Trend Micros Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file.

Risk Information

Base Score
5.5
MODERATE
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.175

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Trend Micro Apex One 2019Windows
Vulnerabilities CVE-2021-25252 are affected in Trend Micro Apex Central 2019Windows
Multiple Vulnerabilities are affected in Trend Micro Apex One 2.3Windows
Multiple Vulnerabilities are affected in Trend Micro Apex Central 2019Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234