VulnerabilityAnalyzed
CVE-2022-26871
Trend Micro Apex Central Arbitrary File Upload Vulnerability
KEVCRITICAL 9.8EPSS 19.6%
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 21 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 19.63% probability · 97th percentile
- CISA KEV
- Listed 31 March 2022 · due 21 April 2022
- Weakness
- CWE-345
- Affected
- trendmicro/apex central · trendmicro/apex one
- Source
- security@trendmicro.com
CISA notes
Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2022-26871
References
- https://appweb.trendmicro.com/supportNews/NewsDetail.aspx?id=4435Vendor Advisory
- https://jvn.jp/vu/JVNVU99107357Third Party Advisory, VDB Entry
- https://success.trendmicro.com/jp/solution/000290660Mitigation, Patch, Vendor Advisory
- https://success.trendmicro.com/solution/000290678Mitigation, Patch, Vendor Advisory
- https://www.jpcert.or.jp/english/at/2022/at220008.htmlThird Party Advisory, VDB Entry
- https://appweb.trendmicro.com/supportNews/NewsDetail.aspx?id=4435Vendor Advisory
- https://jvn.jp/vu/JVNVU99107357Third Party Advisory, VDB Entry
- https://success.trendmicro.com/jp/solution/000290660Mitigation, Patch, Vendor Advisory
- https://success.trendmicro.com/solution/000290678Mitigation, Patch, Vendor Advisory
- https://www.jpcert.or.jp/english/at/2022/at220008.htmlThird Party Advisory, VDB Entry
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-26871US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.