Cyber Resilience

CVE-2022-40139

Trendmicro Apex One 2019

CISA KEVActive ExploitationEUVD Exploited
Published
19 September 2022
Modified
31 October 2025
KEV Added
15 September 2022
Patch / advisory
CVSS Score v3.1 7.2
Click a component to see what it means
Raw vectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.028 85th percentile
Risk Priority 79 floored blend · peak EPSS

Summary

CVE-2022-40139 is a high-severity an unspecified weakness vulnerability in Trendmicro Apex One. Its CVSS base score is 7.2 (High).

Operationally, ranked in the top 15% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.

Deeper analysis AI-assisted summary

Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.

CVE-2022-40139 affects the rollback mechanism in Trend Micro Apex One and Apex One as a Service clients. The flaw stems from improper validation of components used during rollback operations, enabling an authenticated server administrator to direct clients to retrieve and apply an unverified package.

An attacker who first obtains administrative access to the Apex One management console can exploit the issue to trigger remote code execution on connected client systems. The vulnerability carries a CVSS 3.1 score of 7.2, reflecting the high impact once the prerequisite console access is achieved.

Vendor guidance published at success.trendmicro.com/solution/000291528 addresses the issue, and the CVE appears in the CISA Known Exploited Vulnerabilities catalog, indicating that mitigations or updates have been made available to affected customers.

EPSS scores for the vulnerability reached a peak of 0.1344 before receding to the current value of 0.0891.

EU & UK References

Vulnerability Data

Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback…

more

package, which could lead to remote code execution. Please note: an attacker must first obtain Apex One server administration console access in order to exploit this vulnerability.

CWE(s)
KEV Date Added
15 September 2022

Related Threats

CVEs Like This One

CVE-2020-24557Same product: Microsoft Windowsboth on KEV
CVE-2023-30902Same product: Microsoft Windows
CVE-2023-25146Same product: Microsoft Windows
CVE-2023-32556Same product: Microsoft Windows
CVE-2023-34146Same product: Microsoft Windows
CVE-2023-32555Same product: Microsoft Windows
CVE-2023-25148Same product: Microsoft Windows
CVE-2023-32552Same product: Microsoft Windows
CVE-2023-41179Same product: Microsoft Windowsboth on KEV
CVE-2023-32554Same product: Microsoft Windows

Affected Assets

trendmicro
apex one
2019, all versions

Mitigating Controls

No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.

References