CVE-2022-40139
Trend Micro Apex One
Published 19 Sept 2022 · updated 17 Jun 2026 · Analyzed
7.2 High · CVSS 3.1, NVD
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 15 Sept 2022, with a remediation deadline of 6 Oct 2022 for US federal agencies.
Required action: Apply updates per vendor instructions.
Description
Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to remote code execution. Please note: an attacker must first obtain Apex One server administration console access in order to exploit this vulnerability.
References
- success.trendmicro.com/solution/000291528 · Patch, Vendor Advisory
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-40139 · US Government Resource