CISA Known Exploited Vulnerability

CVE-2022-40139

Trend Micro · Apex One and Apex One as a Service

Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability

Date added
BOD 22-01 due date
CWE CWE-353, CWE-641
Ransomware Unknown

CISA description

Trend Micro Apex One and Apex One as a Service contain an improper validation of rollback mechanism components that could lead to remote code execution.

Required action

Apply updates per vendor instructions.