An unrestricted file upload vulnerability in Trend Micro Apex Central could allow a remote attacker to create arbitrary files on affected installations.
Please note: although authentication is required to exploit this vulnerability, this vulnerability could be exploited when the attacker has any valid set of credentials. Also, this vulnerability could be potentially used in combination with another vulnerability to execute arbitrary code.
References
Link | Resource |
---|---|
https://success.trendmicro.com/dcx/s/solution/000296153?language=en_US | Vendor Advisory |
https://www.zerodayinitiative.com/advisories/ZDI-24-077/ | Third Party Advisory VDB Entry |
Configurations
History
No history.
Information
Published : 2024-01-23 21:15
Updated : 2024-01-30 18:40
NVD link : CVE-2023-52324
Mitre link : CVE-2023-52324
CVE.ORG link : CVE-2023-52324
JSON object : View
Products Affected
trendmicro
- apex_central
CWE
CWE-434
Unrestricted Upload of File with Dangerous Type