EXPOSURES › CVE-2023-41179
CVE-2023-41179
HIGH ⌖ ON CISA KEV · EXPLOITEDTrend Micro Apex One and Worry-Free Business Security remote code execution vulnerability
Trend Micro Apex One and Worry-Free Business Security contain a remote code execution vulnerability in the third-party anti-virus uninstaller. An attacker must first obtain administrative console access to exploit this vulnerability. This could lead to remote code execution, posing a significant risk to systems. DIB organizations should ensure they are using the latest updates and patches to mitigate this risk.
Shame score — The vulnerability was actively exploited and could lead to remote code execution, which is a severe risk to the security of systems. The fact that it was exploited before a patch was released further highlights the severity of the issue.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Trend Micro Apex One and Worry-Free Business Security contain an unspecified vulnerability in the third-party anti-virus uninstaller that could allow an attacker to manipulate the module to conduct remote code execution. An attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.
| PRODUCT | STATUS |
|---|---|
| Trend Micro Cloud One for Government Trend Micro Inc. |
In Process |
| Trend Micro Vision One for Government Trend Micro Inc. |
In Process |