Vulnerability record · CVE-2023-32521 · published 26 June 2023
CVE-2023-32521: Trend Micro Mobile Security Enterprise path traversal allows unauthenticated file deletion
Trendmicro · Mobile Security
A path traversal flaw (CWE-22) exists in a specific service DLL of Trend Micro Mobile Security (Enterprise) 9.8 SP5. An unauthenticated remote attacker can abuse it to delete arbitrary files on the host. Because no credentials or user interaction are required, the flaw is reachable by anyone who can send requests to the affected service.
Description
A path traversal exists in a specific service dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an unauthenticated remote attacker to delete arbitrary files.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
Automated analysis
critical priorityCVSS 9.1 with network reachability, no authentication, and high integrity and availability impact, plus a high EPSS score and public exploit reference.
What it is
A path traversal flaw (CWE-22) exists in a specific service DLL of Trend Micro Mobile Security (Enterprise) 9.8 SP5. An unauthenticated remote attacker can abuse it to delete arbitrary files on the host. Because no credentials or user interaction are required, the flaw is reachable by anyone who can send requests to the affected service.
Impact
The attacker gains the ability to delete arbitrary files on the affected server, which can disrupt the service, remove security components, or set up further compromise. Integrity and availability are both rated high; confidentiality is not affected.
Attack surface
Reached over the network via the vulnerable service DLL, per the CVSS vector AV:N/AC:L/PR:N/UI:N. No authentication and no user interaction are needed.
Exploitation
Not listed in CISA KEV and no ransomware association is recorded, but EPSS is high (0.668, 99.3rd percentile) and a third-party advisory is tagged Exploit, indicating public exploit detail exists.
What to do
- Apply the vendor patch referenced in Trend Micro solution 000293106 as the first action.
- Restrict network access to the affected service to trusted management hosts only.
- If the service is not required, disable or uninstall the vulnerable component until patched.
- Monitor and back up critical files on the host so deletions can be detected and restored.
Detection
- Alert on unexpected deletion or disappearance of files in the Mobile Security installation and service directories.
- Monitor service logs and file system audit events for traversal patterns such as ../ sequences in requests to the affected DLL.
- Watch for repeated unauthenticated requests to the vulnerable service from unusual source IPs.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://success.trendmicro.com/dcx/s/solution/000293106?language=en_US | PatchVendor Advisory |
| https://www.tenable.com/security/research/tra-2023-17 | ExploitThird Party Advisory |
| https://success.trendmicro.com/dcx/s/solution/000293106?language=en_US | PatchVendor Advisory |
| https://www.tenable.com/security/research/tra-2023-17 | ExploitThird Party Advisory |
Track CVE-2023-32521 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-32521), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.