← Vulnerability feed

Vulnerability record · CVE-2021-32460 · published 3 June 2021

CVE-2021-32460: Trendmicro maximum security 2021 incorrect permission assignment vulnerability

Trendmicro · Maximum Security 2021

The Trend Micro Maximum Security 2021 (v17) consumer product is vulnerable to an improper access control vulnerability in the installer which could allow a local attacker to escalate privileges on a target machine. Please note than an attacker must already have local user privileges and access on the machine to exploit this vulnerability.

7.8 CVSS 3.1 High EPSS 0.30% · top 79.3% CWE-732 · Incorrect permission assignment
7.8CVSS 3.1 base score, v2 7.2
0.30%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

The Trend Micro Maximum Security 2021 (v17) consumer product is vulnerable to an improper access control vulnerability in the installer which could allow a local attacker to escalate privileges on a target machine. Please note than an attacker must already have local user privileges and access on the machine to exploit this vulnerability.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-32460 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2023-28929Trendmicro antivirus\+ security 2021 uncontrolled search path element vulnerabilityTrend Micro Security 2021, 2022, and 2023 (Consumer) are vulnerable to a DLL Hijacking vulnerability which could allow an attacker to use a specific …EPSS 0.37%7.8CVE-2021-36744Trendmicro maximum security 2019 link following vulnerabilityTrend Micro Security (Consumer) 2021 and 2020 are vulnerable to a directory junction vulnerability which could allow an attacker to exploit the syste…EPSS 0.47%7.2CVE-2021-25251Trendmicro antivirus\+ security 2020 code injection vulnerabilityThe Trend Micro Security 2020 and 2021 families of consumer products are vulnerable to a code injection vulnerability which could allow an attacker t…EPSS 2.6%7.1CVE-2021-44023Trendmicro antivirus\+ security 2021 link following vulnerabilityA link following denial-of-service (DoS) vulnerability in the Trend Micro Security (Consumer) 2021 familiy of products could allow an attacker to abu…EPSS 0.41%4.3CVE-2018-13374FortiOS and FortiADC access control flaw exposes LDAP credentialsFortiOS (6.0.2, 5.6.7 and earlier) and FortiADC (6.1.0, 6.0.0-6.0.1, 5.4.0-5.4.4) contain an improper access control flaw. An attacker can redirect a…KEVEPSS 38%analysed7.8CVE-2022-22960VMware Workspace ONE Access and related products local privilege escalationVMware Workspace ONE Access, Identity Manager, vRealize Automation and related products ship support scripts with incorrect permission assignments (C…KEVEPSS 36%analysed7.8CVE-2021-23874McAfee Total Protection local privilege escalation via self-defense bypassMcAfee Total Protection before 16.0.30 has an improper privilege management flaw that lets a local user bypass the product's self-defense mechanism a…KEVEPSS 1.0%analysed7.8CVE-2019-15752Docker Desktop Community Edition local privilege escalation via writable credential binaryDocker Desktop Community Edition before 2.1.0.1 assigns incorrect permissions to the %PROGRAMDATA%\DockerDesktop\version-bin\ directory, letting a lo…KEVEPSS 49%analysed

Source: NIST National Vulnerability Database (record CVE-2021-32460), CISA KEV, FIRST EPSS (scores of 2026-10-03). This page is refreshed as NVD updates the record.