Umbra Wiki cve cve/CVE-2023-41179
Back to wiki

CVE-2023-41179 — Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability

provenance: imported · CVE: CVE-2023-41179

CVE-2023-41179: Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability

CISA Known Exploited Vulnerability (KEV)

Vendor / project Trend Micro
Product Apex One and Worry-Free Business Security
Date added 2023-09-21
Due date 2023-10-12
Ransomware campaign use Unknown

Description

Trend Micro Apex One and Worry-Free Business Security contain an unspecified vulnerability in the third-party anti-virus uninstaller that could allow an attacker to manipulate the module to conduct remote code execution. An attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.

Required action (CISA)

Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Notes

https://success.trendmicro.com/dcx/s/solution/000294994?language=en_US ; https://nvd.nist.gov/vuln/detail/CVE-2023-41179

References

  • NVD: https://nvd.nist.gov/vuln/detail/CVE-2023-41179
  • KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog