SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityAnalyzed

CVE-2023-41179

Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability

KEVHIGH 7.2EPSS 4.74%

Does this matter?

Known to be exploited in the wild (CISA KEV, CISA remediation deadline 12 October 2023). Treat as an emergency change: patch or isolate now, then hunt for prior compromise.

Description

A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands on an affected installation. Note that an attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.

CVSS 3.1
7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS
4.74% probability · 91th percentile
CISA KEV
Listed 21 September 2023 · due 12 October 2023
Weakness
CWE-94
Affected
trendmicro/apex one · trendmicro/worry-free business security · trendmicro/worry-free business security services
Source
security@trendmicro.com

CISA notes

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. https://success.trendmicro.com/dcx/s/solution/000294994?language=en_US ; https://nvd.nist.gov/vuln/detail/CVE-2023-41179

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.