Trend Micro Worry-Free Business Security (WFBS) Command Execution Vulnerability (000294994)

high Nessus Plugin ID 192566

Synopsis

The remote host is running an application that is affected by a command execution vulnerability.

Description

The remote host is running a version of the Trend Micro WFBS which is affected by a command execution vulnerability in the 3rd party AV uninstaller module contained in Worry-Free Business Security which could allow an attacker to manipulate the module to execute arbitrary commands on an affected installation.

Solution

Apply patch build 2495 or later as advised in the vendor advisory.

See Also

https://success.trendmicro.com/dcx/s/solution/000294994

Plugin Details

Severity: High

ID: 192566

File Name: trendmicro_wfbs_000294994.nasl

Version: 1.1

Type: remote

Agent: windows

Family: Windows

Published: 3/26/2024

Updated: 3/26/2024

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: High

Score: 7.4

CVSS v2

Risk Factor: High

Base Score: 8.3

Temporal Score: 6.9

Vector: CVSS2#AV:N/AC:L/Au:M/C:C/I:C/A:C

CVSS Score Source: CVE-2023-41179

CVSS v3

Risk Factor: High

Base Score: 7.2

Temporal Score: 6.7

Vector: CVSS:3.0/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:F/RL:O/RC:C

Vulnerability Information

Required KB Items: installed_sw/Trend Micro Worry-Free Business Security Advanced

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 9/21/2023

Vulnerability Publication Date: 9/21/2023

CISA Known Exploited Vulnerability Due Dates: 10/12/2023

Reference Information

CVE: CVE-2023-41179