CVE-2022-40139
KEVlargeImproper Validation RCE via Rollback Mechanism in Trend Micro Apex One Clients
CISA: Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability
CVE-2022-40139 is an improper validation flaw in components of the rollback mechanism in Trend Micro Apex One and Apex One as a Service endpoint clients. It is triggered when an Apex One server administrator instructs managed clients to download and apply a rollback package that is not properly verified, allowing a malicious or spoofed package to reach endpoints. An attacker who exploits this gains remote code execution on the affected client machines. Exploitation requires the attacker to first obtain access to the Apex One server administration console, so it typically serves as a post-compromise escalation path that spreads control from the management server to all managed endpoints. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-09-15 and Trend Micro addressed an actively exploited Apex One zero-day, though no public proof-of-concept is known and use in ransomware campaigns is unknown.
What to do: Apply Trend Micro's Apex One updates per the vendor advisory and CISA's required action (September 2022 fix or later), and for Apex One as a Service confirm the SaaS console has pushed the updated agents to all endpoints. Because exploitation requires administration console access, restrict and monitor that console (limit accounts, use strong authentication, review recent logins), rotate admin credentials if compromise is suspected, and hunt for clients that downloaded or executed rollback packages around the compromise window. Ransomware association is unknown, so treat any console compromise as potentially precursor activity.
| Trend Micro Apex One (on-premises) clients | — |
| Trend Micro Apex One as a Service (SaaS) clients | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to remote code execution. Please note: an attacker must first obtain Apex One server administration console access in order to exploit this vulnerability.
- Affected
- Trend Micro Apex One and Apex One as a Service
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- trendmicro
- Products
- apex one
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H