CVE-2021-32466

Severity CVSS v4.0:
Pending analysis
Type:
CWE-427 Uncontrolled Search Path Element
Publication date:
29/09/2021
Last modified:
02/10/2021

Description

An uncontrolled search path element privilege escalation vulnerability in Trend Micro HouseCall for Home Networks version 5.3.1225 and below could allow an attacker to escalate privileges by placing a custom crafted file in a specific directory to load a malicious library. Please note that an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:trendmicro:housecall_for_home_networks:*:*:*:*:*:*:*:* 5.3.1225 (including)
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*