An unrestricted file upload vulnerability in Trend Micro Apex Central could allow a remote attacker to create arbitrary files on affected installations.
Please note: although authentication is required to exploit this vulnerability, this vulnerability could be exploited when the attacker has any valid set of credentials. Also, this vulnerability could be potentially used in combination with another vulnerability to execute arbitrary code.
References
Link | Resource |
---|---|
https://success.trendmicro.com/dcx/s/solution/000296153?language=en_US | Vendor Advisory |
https://www.zerodayinitiative.com/advisories/ZDI-24-077/ | Third Party Advisory VDB Entry |
https://success.trendmicro.com/dcx/s/solution/000296153?language=en_US | Vendor Advisory |
https://www.zerodayinitiative.com/advisories/ZDI-24-077/ | Third Party Advisory VDB Entry |
Configurations
History
21 Nov 2024, 08:39
Type | Values Removed | Values Added |
---|---|---|
References | () https://success.trendmicro.com/dcx/s/solution/000296153?language=en_US - Vendor Advisory | |
References | () https://www.zerodayinitiative.com/advisories/ZDI-24-077/ - Third Party Advisory, VDB Entry |
30 Jan 2024, 18:40
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
First Time |
Trendmicro
Trendmicro apex Central |
|
References | () https://www.zerodayinitiative.com/advisories/ZDI-24-077/ - Third Party Advisory, VDB Entry | |
References | () https://success.trendmicro.com/dcx/s/solution/000296153?language=en_US - Vendor Advisory | |
CPE | cpe:2.3:a:trendmicro:apex_central:2019:-:*:*:*:windows:*:* | |
CWE | CWE-434 |
23 Jan 2024, 21:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-01-23 21:15
Updated : 2024-11-21 08:39
NVD link : CVE-2023-52324
Mitre link : CVE-2023-52324
CVE.ORG link : CVE-2023-52324
JSON object : View
Products Affected
trendmicro
- apex_central
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type