Skip to content
COOEY

EXPOSURES › CVE-2023-41179

CVE-2023-41179

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2023-09-21 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-41179 ↗
⚡ RCE ⌖ EXPLOITED IN THE WILD SHAME 72/100 rceexploited-in-wildunpatched

Trend Micro Apex One and Worry-Free Business Security remote code execution vulnerability

Trend Micro Apex One and Worry-Free Business Security contain a remote code execution vulnerability in the third-party anti-virus uninstaller. An attacker must first obtain administrative console access to exploit this vulnerability. This could lead to remote code execution, posing a significant risk to systems. DIB organizations should ensure they are using the latest updates and patches to mitigate this risk.

Shame score — The vulnerability was actively exploited and could lead to remote code execution, which is a severe risk to the security of systems. The fact that it was exploited before a patch was released further highlights the severity of the issue.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

Trend Micro Apex One and Worry-Free Business Security contain an unspecified vulnerability in the third-party anti-virus uninstaller that could allow an attacker to manipulate the module to conduct remote code execution. An attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.

AFFECTED FEDRAMP PRODUCTS · 2
PRODUCTSTATUS
Trend Micro Cloud One for Government
Trend Micro Inc.
In Process
Trend Micro Vision One for Government
Trend Micro Inc.
In Process