First published: Fri Jan 19 2024(Updated: )
This vulnerability allows remote attackers to create arbitrary files on affected installations of Trend Micro Apex Central. Authentication is required to exploit this vulnerability. The specific flaw exists within the processing of uploaded ZIP files. The issue results from the lack of proper validation of user-supplied data, which can allow the upload of arbitrary files. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of IUSR.
Affected Software | Affected Version | How to fix |
---|---|---|
Trend Micro Apex Central |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of ZDI-CAN-20803 is critical due to its potential for remote file creation by authenticated attackers.
To fix ZDI-CAN-20803, apply the latest security updates provided by Trend Micro for Apex Central.
ZDI-CAN-20803 is caused by insufficient validation in the processing of uploaded ZIP files.
Yes, authentication is required for an attacker to exploit ZDI-CAN-20803.
The affected product for ZDI-CAN-20803 is Trend Micro Apex Central.