Critical Trend Micro vulnerability exploited in the wild (CVE-2023-41179)
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-41179 | Arbitrary command execution in Trend Micro Apex One and Worry-Free Business Security CVE-2023-41179 is a code-injection flaw (CWE-94) in the third-party AV uninstaller module shipped with Trend Micro Apex One (on-premises and SaaS), Worry-Free Business Security, and Worry-Free Business Security Services. An attacker who has first obtained administrative console access on the target system can manipulate this module to execute arbitrary commands. Successful exploitation yields remote code execution on the affected installation with high impact on confidentiality, integrity, and availability (CVSS 3.1: 7.2). Any organization running these Trend Micro endpoint-security management products is affected, especially those whose consoles are reachable by multiple or untrusted administrators. The flaw is being actively exploited in the wild: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-09-21 and Trend Micro released urgent fixes, though no public proof-of-concept is known and ransomware use has not been confirmed. Do: Apply Trend Micro's security patch/hotfix per vendor instructions immediately, or discontinue use of the product if mitigations are unavailable, as required by the CISA KEV listing. Because exploitation requires administrative console access, restrict console reachability to trusted networks or VPN, audit administrative accounts for anomalous activity, and monitor for signs of exploitation given the active in-the-wild abuse. | 7.2 | 5% | KEV |
| largetens of thousands of installations (order of 10^4-10^5) |
Full article285 words · extracted from helpnetsecurity.com · click to collapse
Trend Micro has fixed a critical zero-day vulnerability (CVE-2023-41179) in several of its endpoint security products for enterprises that has been spotted being exploited in the wild.

About CVE-2023-41179
The nature of the flaw hasn’t been revealed, but we know it’s present in the third-party AV uninstaller module provided with the products, and can be exploited to execute arbitrary code with the system privilege on the PC where a vulnerable security agent is installed.
CVE-2023-41179 affects:
- Trend Micro Apex One On Premise (2019)
- Trend Micro Apex One as a Service
- Worry-Free Business Security 10.0 SP1
- Worry-Free Business Security Services (SaaS)
Patches and mitigations
“Trend Micro has observed at least one active attempt of potential exploitation of [CVE-2023-41179] in the wild,” the company shared.
To exploit the vulnerability, attackers must first log in to a vulnerable product’s administration console. Thus, restricting remote access to the console is a way to mitigate risk of exploitation.
Still, patching/updating is the best and preferred course of action because the vulnerability may also be exploited for lateral movement by attackers who have gained access to other company assets via other means.
“Even though an exploit may require several specific conditions to be met, Trend Micro strongly encourages customers to update to the latest builds as soon as possible,” the company stressed.
The vulnerability has been fixed in Trend Micro Apex One as a Service and Worry-Free Business Security Services (SaaS) with patches released in July 2023.
Admins of Trend Micro Apex One On Premise and Worry-Free Business Security should implement the latest patches – SP1 Patch 1 (B12380) and 10.0 SP1 Patch 2495, respectively – as soon as possible.
Attackers have leveraged zero-days in Apex One in the past.
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.helpnetsecurity.com/2023/09/21/cve-2023-41179/