Trend Micro Patches Zero-Day Endpoint Vulnerability
The critical vulnerability involves uninstalling third-party security products and has been used in cyberattacks.
Trend Micro has released an advisory covering a critical zero-day flaw — tracked as CVE-2023-41179 — that affects Apex One, Apex One SaaS, and Worry-Free Business Security.
The vulnerability can be exploited for arbitrary code execution, and it revolves around the "products' ability to uninstall third-party security software."
The advisory, written in Japanese, details how an attacker would need access to a product's administrative console and would have had to have stolen its management console authentication prior to the attack, since the vulnerability can't infiltrate a network on its own.
Trend Micro also noted that this vulnerability has been exploited in the wild, having "confirmed that this vulnerability has been used in actual attacks. We recommend updating to the latest version as soon as possible."
Patches have been released for products impacted by this vulnerability.
About the Author(s)
You May Also Like
Why Effective Asset Management is Critical to Enterprise Cybersecurity
May 21, 2024Finding Your Way on the Path to Zero Trust
May 22, 2024Extending Access Management: Securing Access for all Identities, Devices, and Applications
June 4, 2024Assessing Software Supply Chain Risk
June 6, 2024Preventing Attackers From Wandering Through Your Enterprise Infrastructure
June 19, 2024
Black Hat USA - August 3-8 - Learn More
August 3, 2024Cybersecurity's Hottest New Technologies: What You Need To Know
March 21, 2024