HIGH

CVE-2022-40139

Trendmicro Apex One 2022-09-19 CVSS v3.1
CVSS
7.2
KEV

Description

Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to remote code execution. Please note: an attacker must first obtain Apex One server administration console access in order to exploit this vulnerability.

Summary dbcve.org

The vulnerability exists in the rollback mechanism of Trend Micro Apex One clients, where improper validation of rollback package components allows a malicious server administrator to push unverified rollback packages to client machines, leading to arbitrary code execution on those clients.

Mitigation

Apply the vendor patch for CVE-2022-40139 to all affected Apex One servers and clients. Until patched, strictly limit access to the Apex One server administration console and monitor for unauthorized administrative actions.

Patch Commit

EPSS Score

3.29%
Probability of exploitation in next 30 days
88th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE