HomeUpdatesTrend Micro fixes critical zero-day vulnerability in Apex One

Trend Micro fixes critical zero-day vulnerability in Apex One

Trend Micro has patched a zero-day vulnerability in its endpoint protection solution, Apex One. This vulnerability appears to have been used in attacks and allows remote code execution.

Trend Micro Apex One zero-day

Apex One is a comprehensive device security solution that can be used by businesses of all sizes. The ' Worry-Free Business Security ' suite is designed specifically for small to medium-sized businesses .

The code execution vulnerability is tracked as CVE-2023-41179 and has been rated 9.1 on the CVSS v3 severity scale. This means it is considered “critical.” The vulnerability is located in the third-party uninstaller module that ships with the security.

See also: Mozilla: Fixes zero-day affecting Firefox and Thunderbird

Trend Micro has observed at least one attack attempt via this vulnerability.

Customers are urged to apply the new updates as soon as possible to keep systems .

The vulnerability affects the following products:

  • Trend Micro Apex One 2019
  • Trend Micro Apex One SaaS 2019
  • Worry-Free Business Security (WFBS) 10.0 SP1 (sold as Virus Buster Business Security (Biz) in Japan)
  • Worry-Free Business Security Services (WFBSS) 10.0 SP1 (sold as Virus Buster Business Security Services (VBBSS) in Japan)

See also: Adobe: Critical zero-days threaten Acrobat and Reader

The fixes were made available in the following versions:

  • Apex One 2019 Service Pack 1 – Patch 1 (Build 12380)
  • Apex One SaaS 14.0.12637
  • WFBS Patch 2495
  • WFBSS July 31 update
Trend Micro fixes critical zero-day vulnerability in Apex One
Microsoft Patch Tuesday September 2023: Fixes 59 vulnerabilities

It is worth noting that in order to exploit the CVE-2023-41179 vulnerability in Trend Micro's Apex One, someone must have previously stolen the product's management console credentials and used them to log in.

Exploitation of this type of vulnerability requires an attacker to have access (physical or remote) to a vulnerable machine,” Trend Micro explains.

The Japanese CERT also issued a warning about exploiting the bug.

See also: Google Chrome: Emergency update for zero-day vulnerability

A temporary solution is to restrict access to the product's management console, which would prevent attackers from accessing the endpoint from external locations. However, for full protection, users should install security updates.

Trend Micro typically does not disclose information about attacks that exploit vulnerabilities in its products. In recent years, several bugs in Trend Micro products have been exploited in attacks . Nine such bugs are listed in CISA 's Known Exploited Vulnerabilities Catalog . The most recent zero-day has not yet been added to the list.

Source: www.bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Digital Fortress
Digital Fortresshttps://www.secnews.gr
Pursue Your Dreams & Live!

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS