ZeroHour

CVE-2023-41179

KEVlarge

Arbitrary command execution in Trend Micro Apex One and Worry-Free Business Security

CISA: Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability

CVSS 3.1
7.2 high
EPSS
5%p91
Published
()
KEV added
AI analysis

CVE-2023-41179 is a code-injection flaw (CWE-94) in the third-party AV uninstaller module shipped with Trend Micro Apex One (on-premises and SaaS), Worry-Free Business Security, and Worry-Free Business Security Services. An attacker who has first obtained administrative console access on the target system can manipulate this module to execute arbitrary commands. Successful exploitation yields remote code execution on the affected installation with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.2). Any organization running these Trend Micro endpoint-security management products is affected, especially those whose consoles are reachable by multiple or untrusted administrators. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-09-21 and Trend Micro released urgent fixes, though no public proof-of-concept is known and ransomware use has not been confirmed.

What to do: Apply Trend Micro's security patch/hotfix per vendor instructions immediately, or discontinue use of the product if mitigations are unavailable, as required by the CISA KEV listing. Because exploitation requires administrative console access, restrict console reachability to trusted networks or VPN, audit administrative accounts for anomalous activity, and monitor for signs of exploitation given the active in-the-wild abuse.

Affected
Trend Micro Apex One (on-premises and SaaS)
Trend Micro Worry-Free Business Security
Trend Micro Worry-Free Business Security Services
Estimated exposure
largetens of thousands of installations (order of 10^4-10^5) — Internet-wide scans around the time of disclosure showed thousands of internet-exposed Apex One management consoles, and the Apex One/Worry-Free product lines are broadly deployed across enterprises and SMBs, supporting an…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands on an affected installation. Note that an attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.

CISA Known Exploited Vulnerability
Affected
Trend Micro Apex One and Worry-Free Business Security
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
trendmicro
Products
apex one, worry-free business security, worry-free business security services
Weakness
CWE-94
Vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

In the news