A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands on an affected instal
A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands on an affected installation.
| Vendor | Product | Versions |
|---|---|---|
| Trend Micro, Inc. | Trend Micro Apex One | 2019 (14.0) |
| Trend Micro, Inc. | Trend Micro Apex One | SaaS |
| Trend Micro, Inc. | Trend Micro Worry | Free Business Security — 10.0 SP1 |
| Trend Micro, Inc. | Trend Micro Worry | Free Business Security Services — SaaS |
Yes — actively exploited. Added to the CISA KEV catalog on 2023-09-21. Ransomware use: Unknown.
For the full vendor write-up, exploit chains, and reference implementations, see the references list in section 09.
Open the Sigma generator with a pre-filled prompt for this CVE to draft a starting detection in your stack of choice:
No directly-cited follow-up CVEs in the KB record for this advisory. The references list in section 09 carries the vendor cross-references.