CVE-2023-41179: Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability
A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands on an affected installation. Note that an attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.
Other sources
Trend Micro Apex One and Worry-Free Business Security contain an unspecified vulnerability in the third-party anti-virus uninstaller that could allow an attacker to manipulate the module to conduct remote code execution. An attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Restrict access to the administrative console for Trend Micro Apex One, Worry-Free Business Security, and Worry-Free Business Security Services to trusted IP addresses (for example, via firewall rules or ACLs) to mitigate exploitation that requires administrative console access.
- Compensating control
Discontinue use of Trend Micro Apex One, Worry-Free Business Security, and Worry-Free Business Security Services if vendor mitigations are unavailable.
Event History
Frequently Asked Questions
What is CVE-2023-41179?
CVE-2023-41179 is a remote code execution vulnerability in Trend Micro Apex One and Worry-Free Business Security.
What is the severity of CVE-2023-41179?
The severity of CVE-2023-41179 is high, with a CVSS score of 7.2.
How does CVE-2023-41179 affect the software?
CVE-2023-41179 affects Trend Micro Apex One (both on-prem and SaaS) and Worry-Free Business Security.
How can an attacker exploit CVE-2023-41179?
An attacker can exploit CVE-2023-41179 by manipulating the 3rd party AV uninstaller module to execute arbitrary commands.
Is there a solution for CVE-2023-41179?
Yes, Trend Micro has provided solutions for CVE-2023-41179. Please refer to the references for more information.