SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2022-40139

Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability

KEVHIGH 7.2EPSS 2.87%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 6 October 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to remote code execution. Please note: an attacker must first obtain Apex One server administration console access in order to exploit this vulnerability.

CVSS 3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
2.87% probability · 86th percentile
CISA KEV
Listed 15 September 2022 · due 6 October 2022
Affected
trendmicro/apex one
Source
security@trendmicro.com

CISA notes

Apply updates per vendor instructions. https://success.trendmicro.com/dcx/s/solution/000291528?language=en_US; https://nvd.nist.gov/vuln/detail/CVE-2022-40139

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.