← Back to browse · API

CVE-2023-0587

Severity
CRITICAL
CVSS
9.1
EPSS
0.59585
Risk score
57.25
CISA KEV
No
PoC
No
Published
2023-02-01
Modified
2025-03-27
First seen
2026-08-07
Aliases
EUVD-2023-12627, GHSA-C5W3-R59J-638H
Products
Trend Micro:Trend Micro Apex One Build 11110
Sources
euvd EUVD-2023-12627

Description

A file upload vulnerability in exists in Trend Micro Apex One server build 11110. Using a malformed Content-Length header in an HTTP PUT message sent to URL /officescan/console/html/cgi/fcgiOfcDDA.exe, an unauthenticated remote attacker can upload arbitrary files to the SampleSubmission directory (i.e., \PCCSRV\TEMP\SampleSubmission) on the server. The attacker can upload a large number of large files to fill up the file system on which the Apex One server is installed.

References