CVE-2022-26871
About
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.
Rainforest analyst review
Trend Micro Apex Central, the management console for the company's endpoint protection suite, exposes a file-upload handler that fails to properly validate what it accepts. An unauthenticated remote attacker can push an arbitrary file to the server, and because the upload can land executable content in a location the application will run, that turns directly into remote code execution on the management host. No credentials, no user interaction, just a crafted request to the exposed endpoint.
The irony and the danger here is the target: Apex Central is the central brain that administers security agents across an organization's fleet, so compromising it hands an attacker a trusted, high-privilege vantage point over the very tooling meant to defend the estate. Management consoles like this are often reachable from broad internal networks and sometimes exposed externally for remote administration. Patch to the fixed Apex Central build without delay, restrict access to the console to a small set of administrative hosts, and review upload directories and web logs for unexpected files, since an unauthenticated RCE on a security-management server is the kind of foothold that gets used to disable protection everywhere else.
References
- https://appweb.trendmicro.com/supportNews/NewsDetail.aspx?id=4435
- https://jvn.jp/vu/JVNVU99107357
- https://success.trendmicro.com/jp/solution/000290660
- https://success.trendmicro.com/solution/000290678
- https://www.jpcert.or.jp/english/at/2022/at220008.html
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-26871
Related CVEs
Frequently asked questions
What is CVE-2022-26871?
An arbitrary file upload vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to upload an arbitrary file which could lead to remote code execution.
How severe is CVE-2022-26871?
CVE-2022-26871 carries a CVSS 3.1 base score of 9.8, rated critical. On the Rainforest Risk Index — which weighs the severity alongside how easy the flaw is to reach and how broad its impact is — it scores 99 out of 100, in the critical band.
How is CVE-2022-26871 exploited?
According to the CVSS vector (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H): attack vector Network, attack complexity Low, privileges required None, user interaction None. Impact on confidentiality High, integrity High and availability High.
Which products are affected by CVE-2022-26871?
Public advisories list the following as affected: apex central, apex one. Check the references on this page for the exact versions each vendor confirms.
How do I fix CVE-2022-26871?
Apply the fix the vendor published — the references on this page link to the primary advisories and patches. When patching can't happen right away, reduce the exposure of the affected component and watch it for exploitation attempts. Rainforest customers see this vulnerability correlated to their own assets and prioritized by real exposure, not by score alone.
Empower Your Security Strategy with Rainforest
Discover vulnerabilities early, prioritize critical threats, and protect what truly matters. Rainforest streamlines your security operations, saving you time and reducing costs, so you can focus on what drives your business forward.
