CVE-2021-25252

Severity CVSS v4.0:
Pending analysis
Type:
CWE-400 Uncontrolled Resource Consumption ('Resource Exhaustion')
Publication date:
03/03/2021
Last modified:
08/09/2021

Description

Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:trendmicro:apex_central:2019:-:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:apex_one:2019:-:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:cloud_edge:5.0:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:apex_one:-:-:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:deep_security:10.0:-:*:*:*:*:*:*
cpe:2.3:a:trendmicro:deep_security:11.0:-:*:*:*:*:*:*
cpe:2.3:a:trendmicro:deep_security:12.0:-:*:*:*:*:*:*
cpe:2.3:a:trendmicro:deep_security:20.0:-:*:*:long_term_support:*:*:*
cpe:2.3:a:trendmicro:control_manager:7.0:-:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:a:trendmicro:deep_discovery_analyzer:5.1:-:*:*:*:*:*:*
cpe:2.3:a:trendmicro:deep_discovery_email_inspector:2.5:-:*:*:*:*:*:*


References to Advisories, Solutions, and Tools