CVE-2022-26871criticalunder attackCWE-345

CVE-2022-26871: critical vulnerability in Trend Micro Apex Central

Published · Updated

63Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA.

ssvc Actcvss 9.8epss 19%
from disclosure to weapon
Published on NVDMar 29
CISA KEV+2d
exploitation probability
19%top 3% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2022-04-21

Apply updates per vendor instructions.

In short

An attacker can upload any file to Trend Micro Apex Central without logging in, potentially allowing them to run malicious code on the server.

Technical detail

An unauthenticated remote attacker can exploit an arbitrary file upload vulnerability (CWE-345) in Trend Micro Apex Central to upload malicious files, leading to remote code execution on the affected system. No authentication is required to trigger this vulnerability, making it readily exploitable.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Related CVEs — Trend Micro Apex Central

In the same product, most dangerous first.