Trendmicro Apex One vulnerabilities

161 known vulnerabilities affecting trendmicro/apex_one.

Total CVEs
161
CISA KEV
9
actively exploited
Public exploits
0
Exploited in wild
8
Severity breakdown
CRITICAL8HIGH107MEDIUM46

Vulnerabilities

Page 4 of 9
CVE-2022-45798HIGHCVSS 7.8v20192022-12-24
CVE-2022-45798 [HIGH] CWE-59 CVE-2022-45798: A link following vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Tr A link following vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One as a Service could allow a local attacker to escalate privileges by creating a symbolic link and abusing the service to delete a file. Please note: an attacker must first obtain the ability to execute low-privileged code on the target
nvd
CVE-2022-44650HIGHCVSS 7.8fixed in 14.0.11789v20192022-12-12
CVE-2022-44650 [HIGH] CWE-787 CVE-2022-44650: A memory corruption vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex A memory corruption vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as a Service could allow a local attacker to elevate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability
nvd
CVE-2022-44654HIGHCVSS 7.5fixed in 14.0.11789v20192022-12-12
CVE-2022-44654 [HIGH] CWE-122 CVE-2022-44654: Affected builds of Trend Micro Apex One and Apex One as a Service contain a monitor engine component Affected builds of Trend Micro Apex One and Apex One as a Service contain a monitor engine component that is complied without the /SAFESEH memory protection mechanism which helps to monitor for malicious payloads. The affected component's memory protection mechanism has been updated to enhance product security.
nvd
CVE-2022-44653HIGHCVSS 7.8fixed in 14.0.11789v20192022-12-12
CVE-2022-44653 [HIGH] CWE-22 CVE-2022-44653: A security agent directory traversal vulnerability in Trend Micro Apex One and Apex One as a Service A security agent directory traversal vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
nvd
CVE-2022-44652HIGHCVSS 7.8fixed in 14.0.11789v20192022-12-12
CVE-2022-44652 [HIGH] CWE-755 CVE-2022-44652: An improper handling of exceptional conditions vulnerability in Trend Micro Apex One and Apex One as An improper handling of exceptional conditions vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
nvd
CVE-2022-45797HIGHCVSS 7.1v20192022-12-12
CVE-2022-45797 [HIGH] CVE-2022-45797: An arbitrary file deletion vulnerability in the Damage Cleanup Engine component of Trend Micro Apex An arbitrary file deletion vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One as a Service could allow a local attacker to escalate privileges and delete files on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to expl
nvd
CVE-2022-44651HIGHCVSS 7.0fixed in 14.0.11789v20192022-12-12
CVE-2022-44651 [HIGH] CWE-367 CVE-2022-44651: A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agen A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
nvd
CVE-2022-44649HIGHCVSS 7.8fixed in 14.0.11789v20192022-12-12
CVE-2022-44649 [HIGH] CWE-787 CVE-2022-44649: An out-of-bounds access vulnerability in the Unauthorized Change Prevention service of Trend Micro A An out-of-bounds access vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as a Service could allow a local attacker to elevate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerab
nvd
CVE-2022-44647MEDIUMCVSS 5.5fixed in 14.0.11789v20192022-12-12
CVE-2022-44647 [MEDIUM] CWE-125 CVE-2022-44647: An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This is similar to, but not
nvd
CVE-2022-44648MEDIUMCVSS 5.5fixed in 14.0.11789v20192022-12-12
CVE-2022-44648 [MEDIUM] CVE-2022-44648: An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. This is similar to, but not the sam
nvd
CVE-2022-41746CRITICALCVSS 9.1v20192022-10-10
CVE-2022-41746 [CRITICAL] CWE-425 CVE-2022-41746: A forced browsing vulnerability in Trend Micro Apex One could allow an attacker with access to the A A forced browsing vulnerability in Trend Micro Apex One could allow an attacker with access to the Apex One console on affected installations to escalate privileges and modify certain agent groupings. Please note: an attacker must first obtain the ability to log onto the Apex One web console in order to exploit this vulnerability.
nvd
CVE-2022-41749HIGHCVSS 7.8v20192022-10-10
CVE-2022-41749 [HIGH] CWE-346 CVE-2022-41749: An origin validation error vulnerability in Trend Micro Apex One agents could allow a local attacker An origin validation error vulnerability in Trend Micro Apex One agents could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
nvd
CVE-2022-41744HIGHCVSS 7.0v20192022-10-10
CVE-2022-41744 [HIGH] CWE-367 CVE-2022-41744: A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One Vulnerability Protection integ A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One Vulnerability Protection integrated component could allow a local attacker to escalate privileges and turn a specific working directory into a mount point on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target s
nvd
CVE-2022-41745HIGHCVSS 7.0v20192022-10-10
CVE-2022-41745 [HIGH] CWE-125 CVE-2022-41745: An Out-of-Bounds access vulnerability in Trend Micro Apex One could allow a local attacker to create An Out-of-Bounds access vulnerability in Trend Micro Apex One could allow a local attacker to create a specially crafted message to cause memory corruption on a certain service process which could lead to local privilege escalation on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the t
nvd
CVE-2022-41747HIGHCVSS 7.8v20192022-10-10
CVE-2022-41747 [HIGH] CWE-295 CVE-2022-41747: An improper certification validation vulnerability in Trend Micro Apex One agents could allow a loca An improper certification validation vulnerability in Trend Micro Apex One agents could allow a local attacker to load a DLL file with system service privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
nvd
CVE-2022-41748MEDIUMCVSS 6.7v20192022-10-10
CVE-2022-41748 [MEDIUM] CWE-276 CVE-2022-41748: A registry permissions vulnerability in the Trend Micro Apex One Data Loss Prevention (DLP) module c A registry permissions vulnerability in the Trend Micro Apex One Data Loss Prevention (DLP) module could allow a local attacker with administrative credentials to bypass certain elements of the product's anti-tampering mechanisms on affected installations. Please note: an attacker must first obtain administrative credentials on the target system in
nvd
CVE-2022-40144CRITICALCVSS 9.8v20192022-09-19
CVE-2022-40144 [CRITICAL] CWE-287 CVE-2022-40144: A vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service could allow an attacke A vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service could allow an attacker to bypass the product's login authentication by falsifying request parameters on affected installations.
nvd
CVE-2022-40142HIGHCVSS 7.8v20192022-09-19
CVE-2022-40142 [HIGH] CWE-269 CVE-2022-40142: A security link following local privilege escalation vulnerability in Trend Micro Apex One and Trend A security link following local privilege escalation vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service agents could allow a local attacker to create a writable folder in an arbitrary location and escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged cod
nvd
CVE-2022-40139HIGHCVSS 7.2KEVv20192022-09-19
CVE-2022-40139 [HIGH] CVE-2022-40139: Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Tr Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to remote code execution. Please note: an attacker must first obtain Apex One server ad
nvd
CVE-2022-40143HIGHCVSS 7.3v20192022-09-19
CVE-2022-40143 [HIGH] CWE-59 CVE-2022-40143: A link following local privilege escalation vulnerability in Trend Micro Apex One and Trend Micro Ap A link following local privilege escalation vulnerability in Trend Micro Apex One and Trend Micro Apex One as a Service servers could allow a local attacker to abuse an insecure directory that could allow a low-privileged user to run arbitrary code with elevated privileges. Please note: an attacker must first obtain the ability to execute low-privilege
nvd