Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-41179

Опубликовано: 19 сент. 2023
Источник: nvd
CVSS3: 7.2
EPSS Низкий

Описание

A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands on an affected installation.

Note that an attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.

Уязвимые конфигурации

Конфигурация 1

Одновременно

Одно из

cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:-:*:*:*
cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:saas:*:*:*
cpe:2.3:a:trendmicro:worry-free_business_security:10.0:sp1:*:*:*:*:*:*
cpe:2.3:a:trendmicro:worry-free_business_security_services:-:*:*:*:saas:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

EPSS

Процентиль: 84%
0.02312
Низкий

7.2 High

CVSS3

Дефекты

CWE-94
CWE-94

Связанные уязвимости

CVSS3: 7.2
github
больше 2 лет назад

A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands on an affected installation. Note that an attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.

CVSS3: 9.1
fstec
больше 2 лет назад

Уязвимость модуля удаления сторонних антивирусных продуктов антивирусных программных средств Trend Micro Apex One, Worry-Free Business Security и Worry-Free Business Security Services, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 84%
0.02312
Низкий

7.2 High

CVSS3

Дефекты

CWE-94
CWE-94