Trend Micro users told to update and patch now - here's why

Trend Micro antivirus
(Image credit: Future)

Cybersecurity firm Trend Micro has told users to apply a newly released patch for some of its products immediately, as it looks to address a security flaw that’s being abused in the wild to deliver malware

In a security bulletin, the company said it released a fix for Apex One (version 2019 - on-premise), Apex One as a Service and Agent version 14.0.12637, Worry-Free Business Security (version 10.0. SP1), and Worry-Free Business Security Services (SaaS), and urged users to apply it immediately.

The patch fixes a vulnerability tracked as CVE-2023-41179, a high-severity flaw (9.1 on CVSS) affecting the third-party antivirus uninstaller module that comes bundled with the software. The flaw would “allow an attacker to manipulate the module to execute arbitrary commands on an affected installation,” Trend Micro said.

Abused in the wild

The company also noted that in order to exploit this flaw, the threat actor must first get administrative console access on the target endpoint. Still, the threat seems to be real, as Trend Micro said it "observed at least one active attempt of potential exploitation of this vulnerability in the wild." For organizations that are unable to apply the patch immediately, the workaround is to limit access to the product administration console to trusted networks, only. 

“However, even though an exploit may require several specific conditions to be met, Trend Micro strongly encourages customers to update to the latest builds as soon as possible,” the security pros concluded.

Unfortunately, Trend Micro did not share any more details about the observed attack attempt - namely who the potential victim was, in which industry it operates, or its size. We also don’t know who the attackers were, but we have asked Trend Micro and will update the article if we hear back from them. 

For now, the best way to stay safe is to always update all software and hardware, and have state-of-the-art endpoint protection or firewalls installed. 

More from TechRadar Pro

Sead is a seasoned freelance journalist based in Sarajevo, Bosnia and Herzegovina. He writes about IT (cloud, IoT, 5G, VPN) and cybersecurity (ransomware, data breaches, laws and regulations). In his career, spanning more than a decade, he’s written for numerous media outlets, including Al Jazeera Balkans. He’s also held several modules on content writing for Represent Communications.

Read more
A person at a laptop with a cybersecure lock symbol floating above it.
Hackers are still using old Ivanti bugs to break into networks
Representational image depecting cybersecurity protection
Ivanti reveals major security update, so make sure you're protected
vpn
Ivanti warns another critical security flaw is being attacked
The best free firewall
Sophos hotfixes remote code execution vulnerabilities in Firewall
Digital image of a lock.
Fortinet flags some worrying security bugs coming back from the dead
The best free firewall
Palo Alto Networks PAN-OS sees authentication bypass under attack from hackers
Latest in Security
Close up of a person touching an email icon.
Criminals are using CSS to get around filters and track email usage
DeepSeek on a mobile phone
More US government departments ban controversial AI model DeepSeek
Ransomware
Fortinet firewall bugs are being targeted by LockBit ransomware hackers
Trojan
Microsoft warns of a devious new RAT malware which can avoid detection with apparent ease
NordProtect logo
Standalone identity theft protection from Nord Security is now available
A man holds a smartphone iPhone screen showing various social media apps including YouTube, TikTok, Facebook, Threads, Instagram and X
Ofcom cracks down on UK tech firms, will issue sanctions for illegal content
Latest in News
Perplexity Squid Game Ad
New ad declares Squid Game's real winner is Perplexity AI
Pedro Pascal in Apple's Someday ad promoting the AirPods 4 with Active Noise Cancellation.
Pedro Pascal cures his heartbreak thanks to AirPods 4 (and the power of dance) in this new ad
Frank Grimes confronts Homer Simpson in The Simpsons' Homer's Enemy episode
Disney+ adds a new continuous Simpsons stream, so you no longer have to spend ages choosing an episode
Helly and Mark standing on an artificial hill surrounded by goats in Severance season 2 episode 3
New Apple teaser for Severance season 2 finale suggests we might finally find out what Lumon is doing with those goats, and I don't think it's anything good
Nvidia GR00T N1 humanoid robot
Nvidia is dreaming of trillion-dollar datacentres with millions of GPUs and I can't wait to live in the Omniverse
Foldable iPhone
Apple’s first foldable iPhone could beat the Samsung Galaxy Z Fold 7 in one key way