ZeroHour
Security Affairspublished ()ingested @securityaffairs

Trend Micro addresses actively exploited zero

criticalExploit / PoC exploited in the wildimportance 60CVE-2023-41179

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-41179
Arbitrary command execution in Trend Micro Apex One and Worry-Free Business Security

CVE-2023-41179 is a code-injection flaw (CWE-94) in the third-party AV uninstaller module shipped with Trend Micro Apex One (on-premises and SaaS), Worry-Free Business Security, and Worry-Free Business Security Services. An attacker who has first obtained administrative console access on the target system can manipulate this module to execute arbitrary commands. Successful exploitation yields remote code execution on the affected installation with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.2). Any organization running these Trend Micro endpoint-security management products is affected, especially those whose consoles are reachable by multiple or untrusted administrators. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-09-21 and Trend Micro released urgent fixes, though no public proof-of-concept is known and ransomware use has not been confirmed.

Do: Apply Trend Micro's security patch/hotfix per vendor instructions immediately, or discontinue use of the product if mitigations are unavailable, as required by the CISA KEV listing. Because exploitation requires administrative console access, restrict console reachability to trusted networks or VPN, audit administrative accounts for anomalous activity, and monitor for signs of exploitation given the active in-the-wild abuse.

7.25% KEV
  • Trend Micro Apex One (on-premises and SaaS)
  • Trend Micro Worry-Free Business Security
  • Trend Micro Worry-Free Business Security Services
largetens of thousands of installations (order of 10^4-10^5)
Full article305 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 20, 2023

Trend Micro addressed a zero-day code execution vulnerability (CVE-2023-41179) in Apex One that has been actively exploited in the wild.

Trend Micro has released security updates to patch an actively exploited zero-day vulnerability, tracked as CVE-2023-41179, impacting endpoint security products, including Apex One, Apex One SaaS, and Worry-Free Business Security products. 

According to the security firm the vulnerability has been exploited in attacks. The flaw is related to the products’ ability to uninstall third-party security software.

An attacker can trigger this vulnerability after it has logged into the product’s administrative console. 

“An arbitrary code execution vulnerability has been identified in the Apex One SaaS, Biz, and VBBSS agents’ ability to uninstall third-party security products. To exploit this vulnerability, an attacker would need to be able to log into the product’s administrative console.” reads the advisory published by Trend Micro. Because an attacker would need to have stolen the product’s management console authentication information in advance, they would not be able to infiltrate the target network using this vulnerability alone.”

The vendor recommends customers update their installs to the latest version as soon as possible.

Trend Micro pointed out that the exploitation of this type of flaw typically requires an attacker to have access to the vulnerable device. To mitigate the risk of exploitation the company recommends allowing access only from trusted networks.

Trend Micro has not shared any information regarding the attacks exploiting this vulnerability.

The Japan CERT already published an alert regarding this vulnerability.

“Since the vulnerability is already being exploited in the wild, the users of the affected products are recommended to update the affected system to the latest version as soon as possible.” reads the alert.

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Trend Micro Apex One)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/151095/hacking/trend-micro-apex-one-zero-day-flaw.html