CVE-2021-32466

high

Description

An uncontrolled search path element privilege escalation vulnerability in Trend Micro HouseCall for Home Networks version 5.3.1225 and below could allow an attacker to escalate privileges by placing a custom crafted file in a specific directory to load a malicious library. Please note that an attacker must first obtain the ability to execute low-privileged code on the target system to exploit this vulnerability.

References

https://www.zerodayinitiative.com/advisories/ZDI-21-1112/

https://helpcenter.trendmicro.com/ja-jp/article/TMKA-10621

https://helpcenter.trendmicro.com/en-us/article/tmka-10626

Details

Source: Mitre, NVD

Published: 2021-09-29

Updated: 2026-06-17

Risk Information

CVSS v2

Base Score: 6.9

Vector: CVSS2#AV:L/AC:M/Au:N/C:C/I:C/A:C

Severity: Medium

CVSS v3

Base Score: 7

Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity: High

EPSS

EPSS: 0.0007