CVE-2022-40139: Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability
Trend Micro Apex One and Apex One as a Service contain an improper validation of rollback mechanism components that could lead to remote code execution.
Other sources
Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to remote code execution. Please note: an attacker must first obtain Apex One server administration console access in order to exploit this vulnerability.
Affected Software
Remediation
Patch Available
Event History
Frequently Asked Questions
What is CVE-2022-40139?
CVE-2022-40139 is an improper validation vulnerability in Trend Micro Apex One and Apex One as a Service clients.
How does CVE-2022-40139 affect Trend Micro Apex One and Apex One as a Service?
CVE-2022-40139 allows an Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to remote code execution.
How severe is CVE-2022-40139?
CVE-2022-40139 has a severity rating of 7.2 (high).
What software is affected by CVE-2022-40139?
Trend Micro Apex One and Apex One as a Service clients are affected by CVE-2022-40139.
How can I fix CVE-2022-40139?
To fix CVE-2022-40139, update Trend Micro Apex One and Apex One as a Service clients to the latest version available, as recommended by Trend Micro.