CVE-2022-40139
Trendmicro Apex One 2019
Raw vector
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:HSummary
CVE-2022-40139 is a high-severity an unspecified weakness vulnerability in Trendmicro Apex One. Its CVSS base score is 7.2 (High).
Operationally, ranked in the top 15% of CVEs by exploit likelihood; CISA has added it to the Known Exploited Vulnerabilities catalog.
Deeper analysis AI-assisted summary
Synthesised by an AI model from the NVD description and linked references — a reading aid, not an authoritative source.
CVE-2022-40139 affects the rollback mechanism in Trend Micro Apex One and Apex One as a Service clients. The flaw stems from improper validation of components used during rollback operations, enabling an authenticated server administrator to direct clients to retrieve and apply an unverified package.
An attacker who first obtains administrative access to the Apex One management console can exploit the issue to trigger remote code execution on connected client systems. The vulnerability carries a CVSS 3.1 score of 7.2, reflecting the high impact once the prerequisite console access is achieved.
Vendor guidance published at success.trendmicro.com/solution/000291528 addresses the issue, and the CVE appears in the CISA Known Exploited Vulnerabilities catalog, indicating that mitigations or updates have been made available to affected customers.
EPSS scores for the vulnerability reached a peak of 0.1344 before receding to the current value of 0.0891.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2022-43457
Vulnerability Data
Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback…
more
package, which could lead to remote code execution. Please note: an attacker must first obtain Apex One server administration console access in order to exploit this vulnerability.
- CWE(s)
- KEV Date Added
- 15 September 2022
Related Threats
CVEs Like This One
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.