CVE-2021-25252

MEDIUMCVSS 5.5/10EPSS 0.56%

Last modified

CVE-2021-25252 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file.. EPSS estimates a 0.56% chance of exploitation in the next 30 days.

Description

Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file.

Metrics

CVSS 3.1
5.5/10

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

EPSS Probability
0.56%

42.1th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
TrendmicroApex Central2019
TrendmicroApex One2019
TrendmicroCloud Edge5.0
TrendmicroApex OneAll versions
TrendmicroDeep Security10.0
TrendmicroDeep Security11.0
TrendmicroDeep Security12.0
TrendmicroDeep Security20.0
TrendmicroControl Manager7.0
TrendmicroDeep Discovery Analyzer5.1
TrendmicroDeep Discovery Email Inspector2.5
TrendmicroDeep Discovery Inspector3.8
TrendmicroInterscan Messaging Security Virtual Appliance9.1
TrendmicroInterscan Web Security Virtual Appliance6.5
TrendmicroOfficescanAll versions
TrendmicroPortal Protect2.6
TrendmicroScanmail14.0
TrendmicroScanmail For Ibm Domino5.8
TrendmicroServerprotect For Storage6.0
TrendmicroServerprotect5.8
TrendmicroServerprotect For Network Appliance Filers5.8
TrendmicroSafe Lock1.1
TrendmicroWorry-Free Business Security10.1

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-25252?
Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file.
How severe is CVE-2021-25252?
CVE-2021-25252 has a CVSS score of 5.5/10 (MEDIUM severity). The EPSS model estimates a 0.56% probability of exploitation in the next 30 days.
How do I fix CVE-2021-25252?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-25252?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST