Vulnerability Intelligence Report
Trend Micro Apex One and Worry-Free Business Security Remote Code Execution Vulnerability
CVE-2023-41179
A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute arbitrary commands on an affected installation. Note that an attacker must first obtain administrative console access on the target system in order to exploit this vulnerability.
CISA KEV
SSVC: Active Exploitation
CVSS Base Score
7.2
HIGH
Exploitability:1.3
Impact Score:5.9
EPSS Probability:4.74%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-94 ↗CWE-94 Improper Control of Generation of Code ('Code Injection')
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Trend Micro, Inc. | Trend Micro Apex One | 2019 (14.0) < 14.0.0.12380 (affected) |
| Trend Micro, Inc. | Trend Micro Apex One | SaaS < 14.0.12637 (affected) |
| Trend Micro, Inc. | Trend Micro Worry-Free Business Security | 10.0 SP1 < 10.0 SP1 Build 2495 (affected) |
| Trend Micro, Inc. | Trend Micro Worry-Free Business Security Services | SaaS < 6.7.3578 / 14.3.1105 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | Trend Micro, Inc. · Vendor · Japan |
| Reserved | 2023-08-24T14:57:42 |
| Published | 2023-09-19T13:44:57 |
| Last Updated | 2025-10-21T23:05:37 |
Community Chatter & Buzz