Trend Micro has recently addressed a critical security vulnerability, tracked as CVE-2023-41179, impacting their Apex One and Worry-Free Business Security solutions for Windows. This vulnerability has been actively exploited in real-world attacks, posing a significant threat to affected systems. This advisory provides essential details about the vulnerability, affected products, and recommended actions to mitigate the risk.
The vulnerability exists within a third-party antivirus uninstaller module bundled with Trend Micro’s Apex One and Worry-Free Business Security solutions. If successfully exploited, an attacker with administrative console access can execute arbitrary commands on the affected installation. It’s crucial to note that the attacker must already have administrative console access to the target system for exploitation.
Exploitation of CVE-2023-41179 can lead to unauthorized code execution on affected systems, potentially compromising sensitive data and system integrity. Trend Micro has observed active attempts to exploit this vulnerability in real-world attacks, emphasizing the importance of immediate action.
Trend Micro has reported active exploitation of CVE-2023-41179 in the wild. The Japanese CERT has also issued an alert urging users of the impacted software to upgrade to a secure release promptly. This vulnerability underscores the critical importance of keeping security software up to date to protect against emerging threats.
The SOC teams of OBRELA remain vigilant and are closely monitoring clients’ infrastructure regarding potential exploitation attempts.