#VU72092 Insecure DLL loading in Apex One - CVE-2023-25143
Published: February 9, 2023
Apex One
Trend Micro
Description
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to the application loads DLL libraries in an insecure manner in the Trend Micro Apex One Server installer. A remote attacker can place a specially crafted .dll file on a remote SMB fileshare, trick the victim into launching the installer file and execute arbitrary code on victim's system.