PT-2023-5267 · Trend Micro · Trend Micro Apex One+2

Published

2023-09-19

·

Updated

2026-05-25

·

CVE-2023-41179

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Trend Micro Apex One (on-prem and SaaS) versions (affected versions not specified) Worry-Free Business Security versions (affected versions not specified) Worry-Free Business Security Services versions (affected versions not specified)
Description A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro products could allow an attacker to manipulate the module to execute arbitrary commands on an affected installation. Note that an attacker must first obtain administrative console access on the target system in order to exploit this vulnerability. The vulnerability has been exploited in real-world attacks.
Recommendations For Trend Micro Apex One (on-prem and SaaS), update to the latest version to fix the vulnerability. For Worry-Free Business Security, update to the latest version to fix the vulnerability. For Worry-Free Business Security Services, update to the latest version to fix the vulnerability. As a temporary workaround, consider disabling the vulnerable 3rd party AV uninstaller module until a patch is available.

Fix

Code Injection

OS Command Injection

Weakness Enumeration

Related Identifiers

BDU:2023-05884
CVE-2023-41179

Affected Products

Trend Micro Apex One
Worry-Free Business Security
Worry-Free Business Security Services