CVE-2022-40139 is a high-severity vulnerability affecting Trend Micro Apex One and Apex One as a Service clients, allowing a compromised Apex One server administrator to execute remote code by instructing clients to download an unverified rollback package. With a CVSS score of 7.2, this vulnerability presents a significant risk due to its high impact on confidentiality, integrity, and availability, requiring high privileges for exploitation. It is actively exploited in the wild, as confirmed by its presence in the KEV catalog and multiple media reports, despite the lack of public exploit code. The vulnerability has garnered substantial community discussion and media coverage, indicating widespread awareness and concern.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:trendmicro:apex_one:-:*:*:*:saas:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.