Junglewise Threat Intelligence

CVE-2022-40139: Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability

CVE-2022-40139 · Severity: critical · CVSS 7.2 · Exploited in the wild · Published 2022-09-15

Technologies: Trend Micro Apex One as a Service, Trend Micro Apex One. Vendors: Trend Micro, Trend Micro.

Executive brief

Improper validation of rollback mechanism components in Trend Micro Apex One allows an authenticated administrator to force clients to download unverified packages. This can lead to remote code execution on the affected client endpoints.

Affected products

  • Trend Micro Apex One 2019
  • Trend Micro Apex One as a Service

Timeline

  • 2022-09-15: disclosed
  • 2022-09-15: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2022-09-19: advisory: NVD Published Date
  • 2022-09-15: exploited: Reported as exploited in the wild per advisory and CISA KEV inclusion.

Related threats