Windows security solution Trend Micro Apex One as a gateway for attackers
Attackers can exploit several vulnerabilities in Trend Micro Apex One. Security updates are available.
(Image: solarseven/Shutterstock.com)
Apex One and Apex One as a Service from Trend Micro are vulnerable under Windows. The security solution is supposed to protect computers, but now attackers can exploit six vulnerabilities and attack systems.
Manufacturer advises urgent update
In a post, the developers list the patched versions Apex One SP1 build 13140 and Apex One as a Service December 2024 Monthly Maintenance (202412) Agent version 14.0.14203. The vulnerabilities closed therein (CVE-2024-52048, CVE-2024-52049, CVE-2024-52050, CVE-2024-55631, CVE-2024-55632, CVE-2024-55917) are classified as"high" threat level.
Videos by heise
Attackers must be able to access PCs physically or remotely and be able to execute code with low user rights. If these conditions are met, attackers can acquire higher user rights. Detailed information on how such attacks work is not yet available. It is also unknown whether there are already attacks and how admins can recognize attacked computers.
(des)