CVE-2023-41179 is a critical arbitrary code execution vulnerability (CWE-94) in the third-party AV uninstaller module of Trend Micro Apex One and Worry-Free Business Security products. This flaw allows an attacker with administrative console access to execute arbitrary commands on affected systems. Rated with a CVSS score of 7.2 (HIGH), the vulnerability has a high impact on confidentiality, integrity, and availability. Notably, this zero-day has been actively exploited in the wild, as confirmed by its inclusion in CISA's KEV catalog, and has garnered significant community and media attention, despite no public exploit code being available.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
2019CPE matchmatch criteria | cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:-:*:*:* | ||
2019CPE matchmatch criteria | cpe:2.3:a:trendmicro:apex_one:2019:*:*:*:saas:*:*:* | ||
10.0CPE matchmatch criteria | cpe:2.3:a:trendmicro:worry-free_business_security:10.0:sp1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:a:trendmicro:worry-free_business_security_services:-:*:*:*:saas:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.3 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.