ZeroHour

CVE-2022-40139

KEVlarge

Improper Validation RCE via Rollback Mechanism in Trend Micro Apex One Clients

CISA: Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability

CVSS 3.1
7.2 high
EPSS
3%p86
Published
()
KEV added
AI analysis

CVE-2022-40139 is an improper validation flaw in components of the rollback mechanism in Trend Micro Apex One and Apex One as a Service endpoint clients. It is triggered when an Apex One server administrator instructs managed clients to download and apply a rollback package that is not properly verified, allowing a malicious or spoofed package to reach endpoints. An attacker who exploits this gains remote code execution on the affected client machines. Exploitation requires the attacker to first obtain access to the Apex One server administration console, so it typically serves as a post-compromise escalation path that spreads control from the management server to all managed endpoints. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-09-15 and Trend Micro addressed an actively exploited Apex One zero-day, though no public proof-of-concept is known and use in ransomware campaigns is unknown.

What to do: Apply Trend Micro's Apex One updates per the vendor advisory and CISA's required action (September 2022 fix or later), and for Apex One as a Service confirm the SaaS console has pushed the updated agents to all endpoints. Because exploitation requires administration console access, restrict and monitor that console (limit accounts, use strong authentication, review recent logins), rotate admin credentials if compromise is suspected, and hunt for clients that downloaded or executed rollback packages around the compromise window. Ransomware association is unknown, so treat any console compromise as potentially precursor activity.

Affected
Trend Micro Apex One (on-premises) clients
Trend Micro Apex One as a Service (SaaS) clients
Estimated exposure
largelikely hundreds of thousands of endpoint agents worldwide (order of magnitude); exact count unknown — Apex One is Trend Micro's flagship enterprise endpoint platform with broad enterprise installed bases for both on-premises and SaaS deployments, but the source data contains no install counts or public scan figures, so this is an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to remote code execution. Please note: an attacker must first obtain Apex One server administration console access in order to exploit this vulnerability.

CISA Known Exploited Vulnerability
Affected
Trend Micro Apex One and Apex One as a Service
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
trendmicro
Products
apex one
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news