CVE-2023-52324

HIGH

Trendmicro Apex Central - Unrestricted File Upload

Title source: rule
STIX 2.1

Description

An unrestricted file upload vulnerability in Trend Micro Apex Central could allow a remote attacker to create arbitrary files on affected installations. Please note: although authentication is required to exploit this vulnerability, this vulnerability could be exploited when the attacker has any valid set of credentials. Also, this vulnerability could be potentially used in combination with another vulnerability to execute arbitrary code.

References (2)

Core 2

Scores

CVSS v3 8.8
EPSS 0.0720
EPSS Percentile 91.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-434
Status published
Products (1)
trendmicro/apex_central 2019
Published Jan 23, 2024
Tracked Since Feb 18, 2026