CVE-2023-32529: Trend Micro Apex Central modTMMS SQL Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trend Micro Apex Central. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of deletecertvec requests to the modTMMS endpoint. When parsing the id parameter, the process does not properly validate a user-supplied string before using it to construct SQL queries. An attacker can leverage this vulnerability to execute code in the context of the IUSR user.
Other sources
Vulnerable modules of Trend Micro Apex Central (on-premise) contain vulnerabilities which would allow authenticated users to perform a SQL injection that could lead to remote code execution. Please note: an attacker must first obtain authentication on the target system in order to exploit these vulnerabilities. This is similar to, but not identical to CVE-2023-32530.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability is identified as CVE-2023-32529.
What is the severity of CVE-2023-32529?
CVE-2023-32529 has a severity rating of high.
What software is affected by CVE-2023-32529?
The Trend Micro Apex Central version 2019 on Windows operating systems is affected by CVE-2023-32529.
How does CVE-2023-32529 allow remote attackers to execute arbitrary code?
CVE-2023-32529 allows remote attackers to execute arbitrary code through the processing of delete_cert_vec requests to the modTMMS endpoint.
Are there any references for CVE-2023-32529?
Yes, you can find more information about CVE-2023-32529 at the following references: 1. [Trend Micro Solution](https://success.trendmicro.com/dcx/s/solution/000293107?language=en_US) 2. [Zero Day Initiative Advisory](https://www.zerodayinitiative.com/advisories/ZDI-23-652/)