Windows security solution Trend Micro Apex One as a gateway for attackers

Attackers can exploit several vulnerabilities in Trend Micro Apex One. Security updates are available.

listen Print view

(Image: solarseven/Shutterstock.com)

1 min. read

Apex One and Apex One as a Service from Trend Micro are vulnerable under Windows. The security solution is supposed to protect computers, but now attackers can exploit six vulnerabilities and attack systems.

In a post, the developers list the patched versions Apex One SP1 build 13140 and Apex One as a Service December 2024 Monthly Maintenance (202412) Agent version 14.0.14203. The vulnerabilities closed therein (CVE-2024-52048, CVE-2024-52049, CVE-2024-52050, CVE-2024-55631, CVE-2024-55632, CVE-2024-55917) are classified as"high" threat level.

Videos by heise

Attackers must be able to access PCs physically or remotely and be able to execute code with low user rights. If these conditions are met, attackers can acquire higher user rights. Detailed information on how such attacks work is not yet available. It is also unknown whether there are already attacks and how admins can recognize attacked computers.

(des)

Don't miss any news – follow us on Facebook, LinkedIn or Mastodon.

This article was originally published in German. It was translated with technical assistance and editorially reviewed before publication.