CVE-2022-40139
Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 6 October 2022). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to remote code execution. Please note: an attacker must first obtain Apex One server administration console access in order to exploit this vulnerability.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 2.87% probability · 86th percentile
- CISA KEV
- Listed 15 September 2022 · due 6 October 2022
- Affected
- trendmicro/apex one
- Source
- security@trendmicro.com
CISA notes
Apply updates per vendor instructions. https://success.trendmicro.com/dcx/s/solution/000291528?language=en_US; https://nvd.nist.gov/vuln/detail/CVE-2022-40139
References
- https://success.trendmicro.com/solution/000291528Patch, Vendor Advisory
- https://success.trendmicro.com/solution/000291528Patch, Vendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-40139US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.