CVE-2021-25252
Severity CVSS v4.0:
Pending analysis
Type:
CWE-400
Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
03/03/2021
Last modified:
08/09/2021
Description
Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file.
Impact
Base Score 3.x
5.50
Severity 3.x
MEDIUM
Base Score 2.0
4.90
Severity 2.0
MEDIUM
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:trendmicro:apex_central:2019:-:*:*:*:*:*:* | ||
| cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trendmicro:apex_one:2019:-:*:*:*:*:*:* | ||
| cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trendmicro:cloud_edge:5.0:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trendmicro:apex_one:-:-:*:*:*:*:*:* | ||
| cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trendmicro:deep_security:10.0:-:*:*:*:*:*:* | ||
| cpe:2.3:a:trendmicro:deep_security:11.0:-:*:*:*:*:*:* | ||
| cpe:2.3:a:trendmicro:deep_security:12.0:-:*:*:*:*:*:* | ||
| cpe:2.3:a:trendmicro:deep_security:20.0:-:*:*:long_term_support:*:*:* | ||
| cpe:2.3:a:trendmicro:control_manager:7.0:-:*:*:*:*:*:* | ||
| cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* | ||
| cpe:2.3:a:trendmicro:deep_discovery_analyzer:5.1:-:*:*:*:*:*:* | ||
| cpe:2.3:a:trendmicro:deep_discovery_email_inspector:2.5:-:*:*:*:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



