CVE-2022-40139 - Trend Micro Apex One and Apex One as a Service
AI Vulnerability ContextImproper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to remote code execution. Please note: an attacker must first obtain Apex One server administration console access in order to exploit this vul...
Overview
A source-backed snapshot of this vulnerability.
Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to remote code execution. Please note: an attacker must first obtain Apex One server administration console access in order to exploit this vulnerability.
Vulnerability status
How serious this vulnerability is and whether it is known to be exploited.
- CVE ID
- CVE-2022-40139
- Vendor/project
- Trend Micro
- Product
- Apex One and Apex One as a Service
- Vulnerability name
- Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability
- Date added
- 2022-09-15
- Due date
- 2022-10-06
- Known ransomware campaign use
- Unknown
- CVSS v3
- 7.2
Exploit context
What the vulnerability is about.
Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to remote code execution. Please note: an attacker must first obtain Apex One server administration console access in order to exploit this vulnerability.
Source evidence
Original public records and references for this page.
Original source
Original source links
Open the public records and source datasets used for this page.
