CVE-2021-25252

Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.5 MEDIUM
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
trendmicroCNA
---
---
CVEADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 19%
VendorProductVersion
trendmicrocloud_edge
5.0
trendmicroapex_one
-
trendmicrodeep_security
10.0
trendmicrodeep_security
11.0
trendmicrodeep_security
12.0
trendmicrodeep_security
20.0
trendmicrocontrol_manager
7.0
trendmicrodeep_discovery_analyzer
5.1
trendmicrodeep_discovery_email_inspector
2.5
trendmicrodeep_discovery_inspector
3.8
trendmicrointerscan_messaging_security_virtual_appliance
9.1
trendmicrointerscan_web_security_virtual_appliance
6.5
trendmicroofficescan
-
trendmicroportal_protect
2.6
trendmicroscanmail
14.0
trendmicroscanmail_for_ibm_domino
5.8
trendmicroserverprotect_for_storage
6.0
trendmicroserverprotect
5.8
trendmicroserverprotect_for_network_appliance_filers
5.8
trendmicrosafe_lock
1.1
trendmicroworry-free_business_security
10.1
𝑥
= Vulnerable software versions