Remote denial of service in Trend Micro Apex One



Published: 2023-02-01 | Updated: 2023-02-09
Risk Medium
Patch available YES
Number of vulnerabilities 1
CVE-ID CVE-2023-0587
CWE-ID CWE-285
Exploitation vector Network
Public exploit Public exploit code for vulnerability #1 is available.
Vulnerable software
Subscribe
Apex One
Client/Desktop applications / Antivirus software/Personal firewalls

Vendor Trend Micro

Security Bulletin

This security bulletin contains one medium risk vulnerability.

1) Improper Authorization

EUVDB-ID: #VU71738

Risk: Medium

CVSSv3.1: 6.7 [CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H/E:P/RL:O/RC:C]

CVE-ID: CVE-2023-0587

CWE-ID: CWE-285 - Improper Authorization

Exploit availability: Yes

Description

The vulnerability allows a remote attacker to perform denial of service (DoS) attack.

The vulnerability exists due to missing authorization when processing file uploads at the " /officescan/console/html/cgi/fcgiOfcDDA.exe" URL. A remote non-authenticated attacker can send a specially crafted HTTP PUT request with a malformed Content-Length header, upload an arbitrary number of large files to the SampleSubmission directory (i.e., \\PCCSRV\\TEMP\\SampleSubmission) and consume all available disk space, causing a denial of service condition.

Mitigation

Install updates from vendor's website.

Vulnerable software versions

Apex One: 2019 - SP1 b11561

External links

http://www.tenable.com/security/research/tra-2023-5
http://files.trendmicro.com/documentation/readme/Apex%20One/2020/apex_one_2019_win_sp_b11564_EN_service_pack_Readme.html
http://success.trendmicro.com/dcx/s/solution/000292183?language=en_US
http://success.trendmicro.com/dcx/s/solution/000292209?language=en_US


Q & A

Can this vulnerability be exploited remotely?

Yes. This vulnerability can be exploited by a remote non-authenticated attacker via the Internet.

Is there known malware, which exploits this vulnerability?

No. We are not aware of malware exploiting this vulnerability. However, proof of concept for this vulnerability is available.



###SIDEBAR###