Horizon Alert
Summary of the vulnerability and why it matters
A directory traversal vulnerability in the on-premise version of Trend Micro Apex One could allow an attacker to inject malicious code. This malicious code could then be deployed to agents managed by the affected server.
- Requires local access and admin credentials.
- Affects on-premise Apex One servers.
Attack Path
How an attacker could exploit the issue
A pre-authenticated local attacker with administrative credentials could exploit this by modifying a server table to inject malicious code. This code could then be deployed to agents managed by the compromised Apex One server.
- Requires local access.
- Needs administrative credentials.
- Targets Apex One server.
Live Threat
Current exploitation, exposure, and threat context
Attackers are unlikely to weaponize this vulnerability due to significant prerequisites. Exploitation requires a pre-authenticated local attacker with existing administrative credentials to the on-premise Apex One server. The limited attack surface and high privilege requirement make it unattractive for broad exploitation.
- Requires local access and admin credentials.
- On-premise, internal deployment.
- KEV listed, but exploit conditions are strict.
Priority actions
Operational Fix
Recommended remediation, mitigation, and detection steps
Prioritize reviewing logs and telemetry for signs of pre-authenticated local attacker activity targeting Apex One on-premise servers, especially those with administrative credentials. Inventory all affected Apex One on-premise installations and assess their exposure, considering the potential for code injection for agent deployment.
- Update Apex One to the fixed version.
- Monitor for unusual agent deployment activity.
- Restrict administrative access to Apex One servers.