Trend Micro Patches Zero-Day Endpoint Vulnerability


Trend Micro has released an advisory covering a critical zero-day flaw — tracked as CVE-2023-41179 — that affects Apex One, Apex One SaaS, and Worry-Free Business Security.

The vulnerability can be exploited for arbitrary code execution, and it revolves around the “products’ ability to uninstall third-party security software.”

The advisory, written in Japanese, details how an attacker would need access to a product’s administrative console and would have had to have stolen its management console authentication prior to the attack, since the vulnerability can’t infiltrate a network on its own.