First published: Tue Mar 07 2023(Updated: )
An issue in the Trend Micro Apex One agent could allow an attacker who has previously acquired administrative rights via other means to bypass the protection by using a specifically crafted DLL during a specific update process. Please note: an attacker must first obtain administrative access on the target system via another method in order to exploit this.
Credit: security@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
Trendmicro Apex One | <14.0.11960 | |
Trendmicro Apex One | =2019 | |
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-25147 is a vulnerability in the Trend Micro Apex One agent that allows an attacker with admin access to bypass protection using a specially crafted DLL during a specific update process.
To exploit CVE-2023-25147, an attacker must first obtain administrative access on the target system and then use a malicious DLL during a specific update process.
CVE-2023-25147 affects Trend Micro Apex One versions up to and excluding 14.0.11960, as well as Trend Micro Apex One 2019.
CVE-2023-25147 has a severity rating of 6.7 (medium).
No, Microsoft Windows is not vulnerable to CVE-2023-25147.
To fix CVE-2023-25147, update to a version of Trend Micro Apex One that is not affected by the vulnerability.
You can find more information about CVE-2023-25147 at the following link: [https://success.trendmicro.com/solution/000292209](https://success.trendmicro.com/solution/000292209)
CVE-2023-25147 is associated with CWE-427 (Uncontrolled Search Path Element).