Overview

Trend Micro has released an update for their web-based management console, Apex Central. An arbitrary file upload vulnerability would allow remote code execution (RCE). The company reports that some attacks have been observed in the wild and they have contacted the affected customers.

Following the update, the US Cybersecurity and Infrastructure Security Agency (CISA) has ordered civilian agencies to patch it within the next three weeks.

Impact

A remote attacker could gain control of the admin panel and disable protections.

Vulnerability Detection

Check the running version.

Affected Products

  • SaaS and on-prem
  • Trend Micro Apex Central

Containment, Mitigations & Remediations

The on-prem version requires an update. The SaaS version has been updated automatically.

Indicators of Compromise

None listed.

Threat Landscape

Exploits have been observed in the wild and Trend Micro has reached out to these customers.

Mitre Methodologies

T1190 – Exploit Public-Facing Application

Further Information

IMPORTANT SECURITY BULLETIN: Trend Micro Apex Central Arbitrary File Upload Remote Code Execution (RCE) Vulnerability

Further Threat Intelligence from Quorum Cyber

Headquarters

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

FLORIDA, USA Office

501 E Kennedy Blvd.
STE 1400
Tampa FL 33602

Ontario, Canada Office

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

Contact Us
Address

Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ

501 E Kennedy Blvd
STE 1400
Tampa FL 33602

1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7

HEADQUARTERS
Verdant
2 Redheughs Rigg
Edinburgh
United Kingdom
EH12 9DQ



FLORIDA, USA OFFICE
501 E Kennedy Blvd.
STE 1400
Tampa FL 33602


ONTARIO, CANADA OFFICE
1375 North Service Rd E
Suite 102
Oakville
Ontario L6H 1A7


Legal

Privacy Preference Center

Skip to content