CVE-2022-26871
KEVmoderate1Unauthenticated Arbitrary File Upload RCE in Trend Micro Apex Central
CISA: Trend Micro Apex Central Arbitrary File Upload Vulnerability
CVE-2022-26871 is a critical (CVSS 9.8) arbitrary file upload flaw (CWE-345, insufficient verification of data authenticity) in Trend Micro Apex Central, the central management console for Trend Micro's endpoint protection. An unauthenticated remote attacker can send an upload request to a network-accessible interface without any credentials or user interaction, uploading an arbitrary file that can lead to remote code execution on the server. Successful exploitation gives the attacker code execution with high impact to confidentiality, integrity and availability on the affected management server, potentially providing a foothold into the wider network it manages. Organizations running Trend Micro Apex Central on-premise are affected; CISA also lists Apex One in the product CPE data, while CISA's affected-product entry names Apex Central. The flaw was added to the CISA Known Exploited Vulnerabilities Catalog on 2022-03-31, indicating observed exploitation in the wild, with EPSS estimating a 19.6% probability of exploitation within 30 days; no public PoC is known.
What to do: Apply the updated Apex Central release per Trend Micro's security advisory and the CISA KEV required action (apply updates per vendor instructions); confirm with the vendor which build addresses CVE-2022-26871 for your deployment. Until patched, restrict internet exposure of the Apex Central management console to trusted networks and review the server for unexpected uploaded files or web/server processes launching children, given confirmed in-the-wild exploitation. Organizations managing Apex One endpoints via Apex Central should ensure the management server is prioritized, since compromise could expose endpoint fleet management functions.
| Trend Micro Apex Central | — |
| Trend Micro Apex One | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.
- Affected
- Trend Micro Apex Central
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- trendmicro
- Products
- apex central, apex one
- Weakness
- CWE-345
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H