ZDI-24-897: Trend Micro Apex One modOSCE SQL Injection Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trend Micro Apex One. Authentication is required to exploit this vulnerability. The specific flaw exists within the client management functionality. The issue results from the lack of proper validation of a user-supplied string before using it to construct SQL queries. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of IUSR.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trend Micro Apex One. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2024-39753.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-897?
The severity of ZDI-24-897 is high due to its potential for remote code execution by authenticated attackers.
How do I fix ZDI-24-897?
To fix ZDI-24-897, update Trend Micro Apex One to the latest version as recommended by the vendor.
What type of vulnerability is ZDI-24-897?
ZDI-24-897 is classified as a remote code execution vulnerability affecting Trend Micro Apex One.
Who is affected by ZDI-24-897?
Any installation of Trend Micro Apex One that has not been patched against this vulnerability is affected.
What are the prerequisites for exploiting ZDI-24-897?
Exploiting ZDI-24-897 requires authentication, meaning an attacker must have valid credentials.