CVE-2023-41179
CVE-2023-41179
In short
A vulnerability in Trend Micro antivirus uninstaller allows attackers with admin console access to run arbitrary commands on the system. This is critical because it gives attackers complete control over protected computers.
Technical detail
CWE-94 (Improper Control of Generation of Code) in the AV uninstaller module permits arbitrary code execution through manipulation of the uninstaller functionality. Exploitation requires prior administrative console access to the target system; successful exploitation results in complete command execution privileges on the affected Trend Micro Apex One or Worry-Free Business Security installations.
Summary generated and translated by AI from the official description.
A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands on an affected installation.
Note that an attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
Trend Micro, Inc. · Trend Micro Apex OneTrend Micro, Inc. · Trend Micro Worry-Free Business SecurityTrend Micro, Inc. · Trend Micro Worry-Free Business Security ServicesWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →