Trend Micro addresses actively exploited Apex One zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2022-40139 | Improper Validation RCE via Rollback Mechanism in Trend Micro Apex One Clients CVE-2022-40139 is an improper validation flaw in components of the rollback mechanism in Trend Micro Apex One and Apex One as a Service endpoint clients. It is triggered when an Apex One server administrator instructs managed clients to download and apply a rollback package that is not properly verified, allowing a malicious or spoofed package to reach endpoints. An attacker who exploits this gains remote code execution on the affected client machines. Exploitation requires the attacker to first obtain access to the Apex One server administration console, so it typically serves as a post-compromise escalation path that spreads control from the management server to all managed endpoints. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2022-09-15 and Trend Micro addressed an actively exploited Apex One zero-day, though no public proof-of-concept is known and use in ransomware campaigns is unknown. Do: Apply Trend Micro's Apex One updates per the vendor advisory and CISA's required action (September 2022 fix or later), and for Apex One as a Service confirm the SaaS console has pushed the updated agents to all endpoints. Because exploitation requires administration console access, restrict and monitor that console (limit accounts, use strong authentication, review recent logins), rotate admin credentials if compromise is suspected, and hunt for clients that downloaded or executed rollback packages around the compromise window. Ransomware association is unknown, so treat any console compromise as potentially precursor activity. | 7.2 | 3% | KEV |
| largelikely hundreds of thousands of endpoint agents worldwide (order of magnitude); exact count unknown | |
| CVE-2022-40144 | A vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service could allow an attacker to bypass the product's login authentication by falsifying A vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service could allow an attacker to bypass the product's login authentication by falsifying request parameters on affected installations. NVD description · AI analysis pending | 9.8 group max | 2% |
| — |
Full article296 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 13, 2022

Trend Micro addressed multiple vulnerabilities in its Apex One endpoint security product, including actively exploited zero-day flaws.
Trend Micro announced this week the release of security patches to address multiple vulnerabilities in its Apex One endpoint security product, including a zero-day vulnerability, tracked as CVE-2022-40139 (CVSS 3.0 SCORE 7.2), which is actively exploited.
The CVE-2022-40139 flaw is an improper validation issue related to a rollback function, an agent can exploit the vulnerability to download unverified rollback components and execute arbitrary code.
“We have confirmed an improper validation vulnerability in some of the components used for the rollback function of Apex One and Apex One SaaS. This could allow the agent to download unverified rollback components and execute arbitrary code. An attacker would need to be able to log into the product’s administrative console to exploit this vulnerability. Since the attacker must have previously stolen the authentication information for the product’s management console, it is not possible to infiltrate the target network using this vulnerability alone.” reads the advisory published by Trend Micro. “Trend Micro is aware of attacks using this vulnerability (CVE-2022-40139). We recommend updating to the latest build as soon as possible.”
The company pointed out that the vulnerability could be exploited only by an attacker that had access to authentication data.
Trend Micro did not share details of the attacks exploiting this vulnerability.
Below is the list of the vulnerabilities addressed by the security firm:
| APPLICABLE VULNERABILITY | PRODUCT/COMPONENT/TOOL | CVSS3.0 | SEVERITY |
| SCORE | |||
| CVE-2022-40139 | Apex One | 7.2 | high |
| CVE-2022-40140 | 5.5 | During ~ | |
| CVE-2022-40141 | Apex One SaaS | 5.6 | During ~ |
| CVE-2022-40142 | 7.8 | high | |
| CVE-2022-40143 | 7.3 | high | |
| CVE-2022-40144 | 8.2 | high | |
Follow me on Twitter: @securityaffairs and Facebook
| [adrotate banner=”9″] | [adrotate banner=”12″] |
(SecurityAffairs – hacking, Apex One)
[adrotate banner=”5″]
[adrotate banner=”13″]
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/135689/security/trend-micro-apex-one-zero-day.html