CVE-2023-41179
Trend Micro, Inc. Trend Micro Apex One, Trend Micro, Inc. Trend Micro Worry-Free Business Security, Trend Micro, Inc. Trend Micro Worry-Free Business Security Services
Published 19 Sept 2023 · updated 17 Jun 2026 · Analyzed
Exploited in the wild
CISA added this to its Known Exploited Vulnerabilities catalog on 21 Sept 2023, with a remediation deadline of 12 Oct 2023 for US federal agencies.
Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands on an affected installation. Note that an attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.
References
- jvn.jp/en/vu/JVNVU90967486/ · Third Party Advisory
- success.trendmicro.com/jp/solution/000294706 · Broken Link
- success.trendmicro.com/solution/000294994 · Broken Link
- www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-41179 · US Government Resource