QID 376515
Date Published: 2022-04-06
QID 376515: Trend Micro Apex Central Arbitrary File Upload Remote Code Execution (RCE) Vulnerability
Trend Micro Apex Central is a web-based console that provides centralized management for Trend Micro products and services at the gateway, mail server, file server, and corporate desktop levels.
Affected Versions
Trend Micro Apex Central (on-prem) 2019 prior Build 6016
QID Detection Logic:(Authenticated):
The QID checks for vulnerable version of Trend Micro Apex Central which it fetches out through registry file.
A successful exploit could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.
Solution
Trend Micro has released an advisory detailing various solutions available to fix this issue. Refer to Trend Micro Security Advisory Trend Micro Apex Central for additional information on obtaining the fixes.
Vendor References
- Trend Micro Apex Central -
success.trendmicro.com/dcx/s/solution/000290678?language=en_US
CVEs related to QID 376515
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| Trend Micro Apex Central |
|