An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.
The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.
Link | Tags |
---|---|
https://success.trendmicro.com/solution/000290678 | patch vendor advisory mitigation |
https://success.trendmicro.com/jp/solution/000290660 | patch vendor advisory mitigation |
https://www.jpcert.or.jp/english/at/2022/at220008.html | vdb entry third party advisory |
https://jvn.jp/vu/JVNVU99107357 | vdb entry third party advisory |
https://appweb.trendmicro.com/supportNews/NewsDetail.aspx?id=4435 | vendor advisory |