[CVE-2022-40139] Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability

SecurityDesk
2022.09.15 00:00 조회 10

CISA KEV 정보

취약점명Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability
설명Trend Micro Apex One and Apex One as a Service contain an improper validation of rollback mechanism components that could lead to remote code execution.
조치사항Apply updates per vendor instructions.
랜섬웨어 캠페인 악용Unknown
CWECWE-353 | CWE-641
등록일 (KEV)2022-09-15
조치 기한2022-10-06
추가 참고https://success.trendmicro.com/dcx/s/solution/000291528?language=en_US; https://nvd.nist.gov/vuln/detail/CVE-2022-40139

NVD 상세 정보

CVSS v3.1: 7.2 HIGHCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

설명: Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to remote code execution. Please note: an attacker must first obtain Apex One server administration console access in order to exploit this vulnerability.

참조

This product uses the NVD API but is not endorsed or certified by the NVD.



바로 가기

IT 도구 서랍

→ Unix: 2025-01-15T09:30:00
→ 날짜: 1736934600

→ ASCII: ABC
→ 문자: 65 66 67

ASCII 코드표 — 클릭하면 입력란에 추가

DecHex약어설명
DecHex문자
DecHex문자

→ 유니코드: 홍길동
→ 문자: \ud64d\uae38\ub3d9