← Vulnerability feed

Vulnerability record · CVE-2021-44023 · published 16 December 2021

CVE-2021-44023: Trendmicro antivirus\+ security 2021 link following vulnerability

Trendmicro · Antivirus\+ Security 2021

A link following denial-of-service (DoS) vulnerability in the Trend Micro Security (Consumer) 2021 familiy of products could allow an attacker to abuse the PC Health Checkup feature of the product to create symlinks that would allow modification of files which could lead to a denial-of-service.

7.1 CVSS 3.1 High EPSS 0.41% · top 67.2% CWE-59 · Link following
7.1CVSS 3.1 base score, v2 3.6
0.41%EPSS exploitation probability, 30 days
NoNot in CISA KEV
4Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A link following denial-of-service (DoS) vulnerability in the Trend Micro Security (Consumer) 2021 familiy of products could allow an attacker to abuse the PC Health Checkup feature of the product to create symlinks that would allow modification of files which could lead to a denial-of-service.

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-44023 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

7.8CVE-2023-28929Trendmicro antivirus\+ security 2021 uncontrolled search path element vulnerabilityTrend Micro Security 2021, 2022, and 2023 (Consumer) are vulnerable to a DLL Hijacking vulnerability which could allow an attacker to use a specific …EPSS 0.37%7.8CVE-2021-36744Trendmicro maximum security 2019 link following vulnerabilityTrend Micro Security (Consumer) 2021 and 2020 are vulnerable to a directory junction vulnerability which could allow an attacker to exploit the syste…EPSS 0.47%7.8CVE-2021-32460Trendmicro maximum security 2021 incorrect permission assignment vulnerabilityThe Trend Micro Maximum Security 2021 (v17) consumer product is vulnerable to an improper access control vulnerability in the installer which could a…EPSS 0.30%7.2CVE-2021-25251Trendmicro antivirus\+ security 2020 code injection vulnerabilityThe Trend Micro Security 2020 and 2021 families of consumer products are vulnerable to a code injection vulnerability which could allow an attacker t…EPSS 2.6%7.8CVE-2026-81963Windows Update Stack link-following privilege escalationWindows Update Stack resolves links improperly before accessing files, a link-following flaw (CWE-59) compounded by improper access control (CWE-284)…KEVEPSS 0.39%analysed7.8CVE-2015-5287ABRT abrt-hook-ccpp symlink privilege escalationThe abrt-hook-ccpp helper in Red Hat's Automatic Bug Reporting Tool (ABRT) before 2.7.1 follows symlinks on files with predictable names, letting a l…KEVEPSS 5.0%analysed7.8CVE-2026-41091Microsoft Defender link following allows local privilege elevationMicrosoft Defender's malware protection engine resolves links improperly before accessing files, a link-following flaw (CWE-59). A local attacker wit…KEVEPSS 0.44%analysed7.2CVE-2024-57728SimpleHelp zip slip path traversal allows arbitrary file write and code executionSimpleHelp remote support software v5.5.7 and earlier lets admin users upload a crafted zip file that writes files anywhere on the file system via zi…KEVEPSS 65%analysed

Source: NIST National Vulnerability Database (record CVE-2021-44023), CISA KEV, FIRST EPSS (scores of 2026-10-03). This page is refreshed as NVD updates the record.