QID 378977

Date Published: 2023-11-01

QID 378977: Trend Micro Worry-Free Business Security (WFBS) Arbitrary Code Execution Vulnerability (000294994)

Trend Micro Worry-Free Business Security is a centrally managed anti-malware solution that protects Windows and Mac endpoints from a wide variety of Internet threats.

CVE-2023-41179: Vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Worry-Free Business Security could allow an attacker to manipulate the module to execute arbitrary commands on an affected installation.

Affected Versions:
Trend Micro Worry-Free Business Security version 10.0 SP1

Fixed Version:
Trend Micro Worry-Free Business Security version 10.0 SP1 Patch 2495

Note:
Attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.

QID Detection Logic:(Authenticated):
This QID checks for installed vulnerable version of Trend Micro Worry-Free Business Security (WFBS).

Successful exploitation of this vulnerability may allow an attacker with administrative console access to execute arbitrary code on the target system.

  • CVSS V3 rated as High - 7.2 severity.
  • CVSS V2 rated as High - 6.5 severity.
  • Solution
    Vendor has released patch addressing the vulnerabilities, for more information please refer to Trend Micro Security Advisory (000294994)

    Vendor References

    CVEs related to QID 378977

    Software Advisories
    Advisory ID Software Component Link
    Trend Micro Security Advisory (000294994) URL Logo success.trendmicro.com/dcx/s/solution/000294994?language=en_US