CVE-2023-41179
Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability
Does this matter?
Known to be exploited in the wild (CISA KEV, CISA remediation deadline 12 October 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.
Description
A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands on an affected installation. Note that an attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.
- CVSS 3.1
- 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 4.74% probability · 91th percentile
- CISA KEV
- Listed 21 September 2023 · due 12 October 2023
- Weakness
- CWE-94
- Affected
- trendmicro/apex one · trendmicro/worry-free business security · trendmicro/worry-free business security services
- Source
- security@trendmicro.com
CISA notes
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://success.trendmicro.com/dcx/s/solution/000294994?language=en_US ; https://nvd.nist.gov/vuln/detail/CVE-2023-41179
References
- https://jvn.jp/en/vu/JVNVU90967486/Third Party Advisory
- https://success.trendmicro.com/jp/solution/000294706Broken Link
- https://success.trendmicro.com/solution/000294994Broken Link
- https://jvn.jp/en/vu/JVNVU90967486/Third Party Advisory
- https://success.trendmicro.com/jp/solution/000294706Broken Link
- https://success.trendmicro.com/solution/000294994Broken Link
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-41179US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.