CVE-2023-41179
KEVlargeArbitrary command execution in Trend Micro Apex One and Worry-Free Business Security
CISA: Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability
CVE-2023-41179 is a code-injection flaw (CWE-94) in the third-party AV uninstaller module shipped with Trend Micro Apex One (on-premises and SaaS), Worry-Free Business Security, and Worry-Free Business Security Services. An attacker who has first obtained administrative console access on the target system can manipulate this module to execute arbitrary commands. Successful exploitation yields remote code execution on the affected installation with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.2). Any organization running these Trend Micro endpoint-security management products is affected, especially those whose consoles are reachable by multiple or untrusted administrators. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-09-21 and Trend Micro released urgent fixes, though no public proof-of-concept is known and ransomware use has not been confirmed.
What to do: Apply Trend Micro's security patch/hotfix per vendor instructions immediately, or discontinue use of the product if mitigations are unavailable, as required by the CISA KEV listing. Because exploitation requires administrative console access, restrict console reachability to trusted networks or VPN, audit administrative accounts for anomalous activity, and monitor for signs of exploitation given the active in-the-wild abuse.
| Trend Micro Apex One (on-premises and SaaS) | — |
| Trend Micro Worry-Free Business Security | — |
| Trend Micro Worry-Free Business Security Services | — |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands on an affected installation. Note that an attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.
- Affected
- Trend Micro Apex One and Worry-Free Business Security
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- trendmicro
- Products
- apex one, worry-free business security, worry-free business security services
- Weakness
- CWE-94
- Vector
- CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H