CVE-2021-32458

Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vulnerability which could allow an attacker to issue a specially crafted iotcl which could lead to code execution on affected devices. An attacker must first obtain the ability to execute low-privileged code on the target device in order to exploit this vulnerability.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:trendmicro:home_network_security:*:*:*:en:*:*:*:*
cpe:2.3:a:trendmicro:home_network_security:*:*:*:ja:*:*:*:*
cpe:2.3:a:trendmicro:home_network_security:*:*:*:zh:*:*:*:*

History

07 Jun 2021, 19:08

Type Values Removed Values Added
CWE CWE-787
CPE cpe:2.3:a:trendmicro:home_network_security:*:*:*:en:*:*:*:*
cpe:2.3:a:trendmicro:home_network_security:*:*:*:ja:*:*:*:*
cpe:2.3:a:trendmicro:home_network_security:*:*:*:zh:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 7.2
v3 : 7.8
References (MISC) https://talosintelligence.com/vulnerability_reports/TALOS-2021-1231 - (MISC) https://talosintelligence.com/vulnerability_reports/TALOS-2021-1231 - Third Party Advisory
References (MISC) https://helpcenter.trendmicro.com/en-us/article/TMKA-10337 - (MISC) https://helpcenter.trendmicro.com/en-us/article/TMKA-10337 - Vendor Advisory

03 Jun 2021, 15:15

Type Values Removed Values Added
Summary A privilege escalation vulnerability exists in the tdts.ko chrdev_ioctl_handle functionality of Trend Micro, Inc. Home Network Security 6.1.567. A specially crafted ioctl can lead to code execution. An attacker can issue an ioctl to trigger this vulnerability. Trend Micro Home Network Security version 6.6.604 and earlier is vulnerable to an iotcl stack-based buffer overflow vulnerability which could allow an attacker to issue a specially crafted iotcl which could lead to code execution on affected devices. An attacker must first obtain the ability to execute low-privileged code on the target device in order to exploit this vulnerability.
References
  • {'url': 'https://www.talosintelligence.com/vulnerability_reports/TALOS-2021-1231', 'name': 'https://www.talosintelligence.com/vulnerability_reports/TALOS-2021-1231', 'tags': [], 'refsource': 'MISC'}
  • (MISC) https://helpcenter.trendmicro.com/en-us/article/TMKA-10337 -

27 May 2021, 11:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-05-27 11:15

Updated : 2024-02-04 21:47


NVD link : CVE-2021-32458

Mitre link : CVE-2021-32458

CVE.ORG link : CVE-2021-32458


JSON object : View

Products Affected

trendmicro

  • home_network_security
CWE
CWE-787

Out-of-bounds Write