OS Command Injection in Worry-Free Business Security and Apex One - CVE-2023-41179
Published: September 19, 2023
Vulnerability details
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper input validation within the third-party AV uninstaller module shipped with the software. A local user can execute arbitrary commands with elevated privileges.
Note, the vulnerability is being actively exploited in the wild.
Affected software
Apex One
How to mitigate CVE-2023-41179
Apex One - update to SP1 b12380