CVE-2023-41179

unknown KEV
Published 2023-09-21 · Modified 2023-09-21
CVSS v3
CVSS v2
VIR risk
1.5

Description

Trend Micro Apex One and Worry-Free Business Security contain an unspecified vulnerability in the third-party anti-virus uninstaller that could allow an attacker to manipulate the module to conduct remote code execution. An attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.

CISA KEV

Vendor
Trend Micro
Product
Apex One and Worry-Free Business Security
Due date
2023-10-12

Predictions

Exploit likelihood
99%
Patch ETA

Heuristic predictions, AS-IS, for prioritization only.

Mitigations

vendor Authored 2026-05-27

Vendor advisory: cisa-kev — https://success.trendmicro.com/dcx/s/solution/000294994?language=en_US ; https://nvd.nist.gov/vuln/detail/CVE-2023-41179

Exploits

References

Verify integrity in audit chain (admin only). AS-IS.