CVE-2022-40139

Trend Micro Apex One

Published 19 Sept 2022 · updated 17 Jun 2026 · Analyzed

7.2 High · CVSS 3.1, NVD

Exploited in the wild

CISA added this to its Known Exploited Vulnerabilities catalog on 15 Sept 2022, with a remediation deadline of 6 Oct 2022 for US federal agencies.

Required action: Apply updates per vendor instructions.

Description

Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to remote code execution. Please note: an attacker must first obtain Apex One server administration console access in order to exploit this vulnerability.

References