Executive brief
A vulnerability in the third-party anti-virus uninstaller module within Trend Micro Apex One and Worry-Free Business Security allows for remote code execution. An attacker with administrative console access can manipulate the module to execute arbitrary commands on the target system.
Affected products
- Trend Micro Apex One (on-prem and SaaS) 2019
- Trend Micro Worry-Free Business Security 10.0 SP1
- Trend Micro Worry-Free Business Security Services (SaaS)
Timeline
- 2023-09-21: disclosed
- 2023-09-21: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-09-21: exploited: Reported as exploited in the wild.