QID 377592
Date Published: 2022-09-15
QID 377592: Trend Micro Apex One (On-Prem) Multiple Vulnerabilities (000291528) (September 2022) (Zero Day)
Trend Micro Apex One protection offers advanced automated threat detection and response against an ever-growing variety of threats, including file-less and ransomware.
Trend Micro is affected with below vulnerabilities
CVE-2022-40139: Improper Validation of Rollback Mechanism Components RCE Vulnerability
CVE-2022-40140: Origin Validation Error Denial-of-Service Vulnerability
CVE-2022-40141: Information Disclosure Vulnerability
CVE-2022-40142: Agent Link Following Local Privilege Escalation Vulnerability
CVE-2022-40143: Link Following Local Privilege Escalation Vulnerability
CVE-2022-40144: Login Authentication Bypass Vulnerability
Affected Versions
Trend Micro Apex 2019 (On-Prem) prior to Build 9601
QID Detection Logic:(Authenticated):
The QID checks for vulnerable version of Trend Micro Apex which it fetches out through registry file.
Successful exploitation could compromise Confidentiality, Integrity and Authenticity
- Trend Micro 000291528 -
success.trendmicro.com/dcx/s/solution/000291528?language=en_US
CVEs related to QID 377592
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| 000291528 |
|