SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2022-26871

Trend Micro Apex Central Arbitrary File Upload Vulnerability

KEVCRITICAL 9.8EPSS 19.6%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 21 April 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.

CVSS 3.1
9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS
19.63% probability · 97th percentile
CISA KEV
Listed 31 March 2022 · due 21 April 2022
Weakness
CWE-345
Affected
trendmicro/apex central · trendmicro/apex one
Source
security@trendmicro.com

CISA notes

Apply updates per vendor instructions. https://nvd.nist.gov/vuln/detail/CVE-2022-26871

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.