Vulnerability record · CVE-2022-40139 · published 19 September 2022
CVE-2022-40139: Trend Micro Apex One rollback package validation flaw enables RCE
Trendmicro · Apex One
Trend Micro Apex One and Apex One as a Service clients fail to properly validate components used by the rollback mechanism. An Apex One server administrator can direct affected clients to download an unverified rollback package, which can result in remote code execution on those clients.
Description
Improper validation of some components used by the rollback mechanism in Trend Micro Apex One and Trend Micro Apex One as a Service clients could allow a Apex One server administrator to instruct affected clients to download an unverified rollback package, which could lead to remote code execution. Please note: an attacker must first obtain Apex One server administration console access in order to exploit this vulnerability.
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Automated analysis
high priorityIt is in CISA KEV with confirmed exploitation and enables remote code execution, though exploitation requires prior server admin access.
What it is
Trend Micro Apex One and Apex One as a Service clients fail to properly validate components used by the rollback mechanism. An Apex One server administrator can direct affected clients to download an unverified rollback package, which can result in remote code execution on those clients.
Impact
An attacker with Apex One server administration console access can push an unverified rollback package to managed clients and execute code on them, gaining control of endpoints under that server.
Attack surface
Reached over the network through the Apex One server administration console; the CVSS vector shows network attack, low complexity, no user interaction, but high privileges required, meaning valid server admin access is a precondition.
Exploitation
Listed in CISA KEV with a 2022-10-06 remediation due date, indicating known exploitation; EPSS 30-day probability is about 3.3 percent (87.9th percentile).
What to do
- Apply the vendor patch per Trend Micro solution 000291528 as the first action.
- Restrict and audit Apex One server administration console access, enforcing least privilege and strong authentication.
- Monitor and alert on unexpected rollback package downloads or rollback operations initiated on clients.
- Verify integrity of rollback packages and server-side package repositories where feasible.
- Review KEV guidance and confirm remediation status across all Apex One and Apex One as a Service deployments.
Detection
- Alert on rollback package deployment events originating from unusual or unauthorized admin accounts.
- Monitor Apex One server logs for rollback instructions sent to clients outside normal maintenance windows.
- Hunt for unexpected process execution on managed endpoints following rollback activity.
- Track console logins and privilege changes on the Apex One server for signs of compromised admin credentials.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2022-40139 to the Known Exploited Vulnerabilities catalog on 15 September 2022 as "Trend Micro Apex One and Apex One as a Service Improper Validation Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 6 October 2022.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://success.trendmicro.com/solution/000291528 | PatchVendor Advisory |
| https://success.trendmicro.com/solution/000291528 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2022-40139 | US Government Resource |
Track CVE-2022-40139 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2022-40139), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.