Vulnerability Description
A path traversal vulnerability in the Trend Micro Apex One and Apex One as a Service could allow an unauthenticated attacker to upload an arbitrary file to the Management Server which could lead to remote code execution with system privileges.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trendmicro | Apex One | < 14.0.12105 |
| Microsoft | Windows | - |
Related Weaknesses (CWE)
References
- https://success.trendmicro.com/dcx/s/solution/000293108?language=en_USPatchVendor Advisory
- https://success.trendmicro.com/dcx/s/solution/000293108?language=en_USPatchVendor Advisory
FAQ
What is CVE-2023-32557?
CVE-2023-32557 is a vulnerability with a CVSS score of 9.8 (CRITICAL). A path traversal vulnerability in the Trend Micro Apex One and Apex One as a Service could allow an unauthenticated attacker to upload an arbitrary file to the Management Server which could lead to re...
How severe is CVE-2023-32557?
CVE-2023-32557 has been rated CRITICAL with a CVSS base score of 9.8/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2023-32557?
Check the references section above for vendor advisories and patch information. Affected products include: Trendmicro Apex One, Microsoft Windows.