ZeroHour

CVE-2022-26871

KEVmoderate1

Unauthenticated Arbitrary File Upload RCE in Trend Micro Apex Central

CISA: Trend Micro Apex Central Arbitrary File Upload Vulnerability

CVSS 3.1
9.8 critical
EPSS
20%p97
Published
()
KEV added
AI analysis

CVE-2022-26871 is a critical (CVSS 9.8) arbitrary file upload flaw (CWE-345, insufficient verification of data authenticity) in Trend Micro Apex Central, the central management console for Trend Micro's endpoint protection. An unauthenticated remote attacker can send an upload request to a network-accessible interface without any credentials or user interaction, uploading an arbitrary file that can lead to remote code execution on the server. Successful exploitation gives the attacker code execution with high impact to confidentiality, integrity and availability on the affected management server, potentially providing a foothold into the wider network it manages. Organizations running Trend Micro Apex Central on-premise are affected; CISA also lists Apex One in the product CPE data, while CISA's affected-product entry names Apex Central. The flaw was added to the CISA Known Exploited Vulnerabilities Catalog on 2022-03-31, indicating observed exploitation in the wild, with EPSS estimating a 19.6% probability of exploitation within 30 days; no public PoC is known.

What to do: Apply the updated Apex Central release per Trend Micro's security advisory and the CISA KEV required action (apply updates per vendor instructions); confirm with the vendor which build addresses CVE-2022-26871 for your deployment. Until patched, restrict internet exposure of the Apex Central management console to trusted networks and review the server for unexpected uploaded files or web/server processes launching children, given confirmed in-the-wild exploitation. Organizations managing Apex One endpoints via Apex Central should ensure the management server is prioritized, since compromise could expose endpoint fleet management functions.

Affected
Trend Micro Apex Central
Trend Micro Apex One
Estimated exposure
moderate≈1,000–10,000 on-premise management servers worldwide (estimated) — Apex Central is an enterprise on-premise management console typically deployed once per organization rather than as a mass-market endpoint product, so exposure is bounded by enterprise adoption rather than end-user counts; no public…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.

CISA Known Exploited Vulnerability
Affected
Trend Micro Apex Central
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
trendmicro
Products
apex central, apex one
Weakness
CWE-345
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In the news