EXPOSURES › CVE-2022-40139
CVE-2022-40139
HIGH ⌖ ON CISA KEV · EXPLOITEDTrend Micro's Apex One and Apex One as a Service exposed to remote code execution due to improper validation of rollback mechanisms, actively exploited in the wild.
Trend Micro's Apex One and Apex One as a Service suffered an active remote code execution vulnerability due to inadequate validation of rollback mechanisms, leading to exploitation in the wild.
Shame score — Active exploitation in the wild without a known patch, indicating negligence in security practices.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Trend Micro Apex One and Apex One as a Service contain an improper validation of rollback mechanism components that could lead to remote code execution.
| PRODUCT | STATUS |
|---|---|
| Trend Micro Cloud One for Government Trend Micro Inc. |
In Process |
| Trend Micro Vision One for Government Trend Micro Inc. |
In Process |