PT-2023-5267 · Trend Micro · Trend Micro Apex One+2
Published
2023-09-19
·
Updated
2026-05-25
·
CVE-2023-41179
CVSS v2.0
9.0
High
| Vector | AV:N/AC:L/Au:S/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Trend Micro Apex One (on-prem and SaaS) versions (affected versions not specified)
Worry-Free Business Security versions (affected versions not specified)
Worry-Free Business Security Services versions (affected versions not specified)
Description
A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro products could allow an attacker to manipulate the module to execute arbitrary commands on an affected installation. Note that an attacker must first obtain administrative console access on the target system in order to exploit this vulnerability. The vulnerability has been exploited in real-world attacks.
Recommendations
For Trend Micro Apex One (on-prem and SaaS), update to the latest version to fix the vulnerability.
For Worry-Free Business Security, update to the latest version to fix the vulnerability.
For Worry-Free Business Security Services, update to the latest version to fix the vulnerability.
As a temporary workaround, consider disabling the vulnerable 3rd party AV uninstaller module until a patch is available.
Fix
Code Injection
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trend Micro Apex One
Worry-Free Business Security
Worry-Free Business Security Services