PT-2022-2180 · Trend Micro · Trend Micro Deep Discovery Inspector+2

Published

2022-03-29

·

Updated

2025-12-22

·

CVE-2022-26871

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Trend Micro Apex Central (affected versions not specified)
Description The issue is related to an arbitrary file upload vulnerability that could allow an unauthenticated remote attacker to upload an arbitrary file, potentially leading to remote code execution. There have been reports of at least one active attempt to exploit this vulnerability in real-world conditions. The exploitation is considered complex and requires specific conditions. Trend Micro has released patches for SaaS versions and an update for local installations, and has also provided rules and filters for protection against exploitation attempts.
Recommendations At the moment, there is no information about specific affected versions that contains a fix for this vulnerability. However, it is recommended to update to the latest version, specifically the update 3 (build 6016) for local installations of Apex Central, as soon as possible to mitigate the risk of exploitation. Additionally, consider applying the provided rules and filters for Trend Micro Cloud One and Trend Micro Deep Discovery Inspector to protect against attempts to exploit this issue.

Fix

RCE

Insufficient Verification of Data Authenticity

Unrestricted File Upload

Weakness Enumeration

Related Identifiers

BDU:2022-02205
CVE-2022-26871

Affected Products

Trend Micro Apex Central
Trend Micro Cloud One
Trend Micro Deep Discovery Inspector