#VU80895 OS Command Injection in Apex One and Worry-Free Business Security - CVE-2023-41179
Published: September 19, 2023
Apex One
Worry-Free Business Security
Trend Micro
Description
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to improper input validation within the third-party AV uninstaller module shipped with the software. A local user can execute arbitrary commands with elevated privileges.
Note, the vulnerability is being actively exploited in the wild.