← Vulnerability feed

Vulnerability record · CVE-2023-32521 · published 26 June 2023

CVE-2023-32521: Trend Micro Mobile Security Enterprise path traversal allows unauthenticated file deletion

Trendmicro · Mobile Security

A path traversal flaw (CWE-22) exists in a specific service DLL of Trend Micro Mobile Security (Enterprise) 9.8 SP5. An unauthenticated remote attacker can abuse it to delete arbitrary files on the host. Because no credentials or user interaction are required, the flaw is reachable by anyone who can send requests to the affected service.

9.1 CVSS 3.1 Critical EPSS 67% · top 0.7% CWE-22 · Path traversal
9.1CVSS 3.1 base score
67%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
4References, 2 tagged exploit
17 Jun 2026Last modified by NVD

Description

A path traversal exists in a specific service dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an unauthenticated remote attacker to delete arbitrary files.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

critical priorityCVSS 9.1 with network reachability, no authentication, and high integrity and availability impact, plus a high EPSS score and public exploit reference.

What it is

A path traversal flaw (CWE-22) exists in a specific service DLL of Trend Micro Mobile Security (Enterprise) 9.8 SP5. An unauthenticated remote attacker can abuse it to delete arbitrary files on the host. Because no credentials or user interaction are required, the flaw is reachable by anyone who can send requests to the affected service.

Impact

The attacker gains the ability to delete arbitrary files on the affected server, which can disrupt the service, remove security components, or set up further compromise. Integrity and availability are both rated high; confidentiality is not affected.

Attack surface

Reached over the network via the vulnerable service DLL, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication and no user interaction are needed.

Exploitation

Not listed in CISA KEV and no ransomware association is recorded, but EPSS is high (0.668, 99.3rd percentile) and a third-party advisory is tagged Exploit, indicating public exploit detail exists.

What to do

  • Apply the vendor patch referenced in Trend Micro solution 000293106 as the first action.
  • Restrict network access to the affected service to trusted management hosts only.
  • If the service is not required, disable or uninstall the vulnerable component until patched.
  • Monitor and back up critical files on the host so deletions can be detected and restored.

Detection

  • Alert on unexpected deletion or disappearance of files in the Mobile Security installation and service directories.
  • Monitor service logs and file system audit events for traversal patterns such as ../ sequences in requests to the affected DLL.
  • Watch for repeated unauthenticated requests to the vulnerable service from unusual source IPs.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-32521 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2019-19690Trendmicro mobile security weak password requirements vulnerabilityTrend Micro Mobile Security for Android (Consumer) versions 10.3.1 and below on Android 8.0+ has an issue in which an attacker could bypass the produ…EPSS 1.5%9.8CVE-2017-14078Trend Micro Mobile Security SQL injection allows remote code executionTrend Micro Mobile Security (Enterprise) before 9.7 Patch 3 contains SQL injection vulnerabilities that let remote attackers execute arbitrary code o…EPSS 50%analysed9.8CVE-2017-14080Trendmicro mobile security improper authentication vulnerabilityAuthentication bypass vulnerability in Trend Micro Mobile Security (Enterprise) versions before 9.7 Patch 3 allows attackers to access a specific par…EPSS 3.0%9.1CVE-2022-40980Trendmicro mobile security vulnerabilityA potential unathenticated file deletion vulnerabilty on Trend Micro Mobile Security for Enterprise 9.8 SP5 could allow an attacker with access to th…EPSS 1.2%8.8CVE-2023-32523Trendmicro mobile security improper authentication vulnerabilityAffected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote user to bypass authentication an…EPSS 2.6%8.8CVE-2023-32524Trendmicro mobile security improper authentication vulnerabilityAffected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote user to bypass authentication an…EPSS 2.6%8.8CVE-2023-32527Trendmicro mobile security code injection vulnerabilityTrend Micro Mobile Security (Enterprise) 9.8 SP5 contains vulnerable .php files that could allow a remote attacker to execute arbitrary code on affec…EPSS 2.9%8.8CVE-2023-32528Trendmicro mobile security code injection vulnerabilityTrend Micro Mobile Security (Enterprise) 9.8 SP5 contains vulnerable .php files that could allow a remote attacker to execute arbitrary code on affec…EPSS 3.0%

Source: NIST National Vulnerability Database (record CVE-2023-32521), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.