CVE-2023-52329: Trend Micro Apex Central Cross-Site Scripting Remote Code Execution Vulnerability
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. Please note this vulnerability is similar, but not identical to CVE-2023-52326.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trend Micro Apex Central. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the multiple parameters provided to the modDLPTemplateMatchdrildown.php component. The issue results from the lack of proper validation of user-supplied data, which can lead to the injection of arbitrary script. An attacker can leverage this vulnerability to execute script in the context of the current user.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-52329?
CVE-2023-52329 has a high severity rating due to its potential for allowing remote code execution through XSS attacks.
How do I fix CVE-2023-52329?
To fix CVE-2023-52329, update to the latest version of Trend Micro Apex Central that addresses this vulnerability.
What impact does CVE-2023-52329 have on my system?
CVE-2023-52329 can lead to unauthorized execution of code on affected servers, compromising system security.
Is CVE-2023-52329 related to any other vulnerabilities?
Yes, CVE-2023-52329 is similar to CVE-2023-52326, highlighting a broader issue in the software's security.
Who is affected by CVE-2023-52329?
Users of Trend Micro Apex Central, especially those running version 2019, are affected by CVE-2023-52329.