Junglewise Threat Intelligence

CVE-2023-41179: Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability

CVE-2023-41179 · Severity: critical · CVSS 7.2 · Exploited in the wild · Published 2023-09-21

Technologies: Trend Micro Apex One as a Service, Trend Micro Apex One. Vendors: Trend Micro, Trend Micro.

Executive brief

A vulnerability in the third-party anti-virus uninstaller module within Trend Micro Apex One and Worry-Free Business Security allows for remote code execution. An attacker with administrative console access can manipulate the module to execute arbitrary commands on the target system.

Affected products

  • Trend Micro Apex One (on-prem and SaaS) 2019
  • Trend Micro Worry-Free Business Security 10.0 SP1
  • Trend Micro Worry-Free Business Security Services (SaaS)

Timeline

  • 2023-09-21: disclosed
  • 2023-09-21: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-09-21: exploited: Reported as exploited in the wild.

Related threats