Unrestricted File Upload Vulnerability in Trend Micro Apex Central
CVE-2023-52324

8.8HIGH

Key Information:

Vendor
CVE Published:
23 January 2024

Summary

An unrestricted file upload vulnerability exists in Trend Micro Apex Central that enables a remote attacker to create arbitrary files on vulnerable installations. While the presence of valid credentials is necessary for exploitation, this vulnerability poses a significant risk as it can be leveraged to upload malicious files. Furthermore, it may be utilized in conjunction with other vulnerabilities to facilitate the execution of arbitrary code, thus compromising the integrity and security of the affected systems.

Affected Version(s)

Trend Micro Apex Central 2019 < 8.0.0.6570

References

CVSS V3.1

Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.