Zero-day Directory Traversal pada Trend Micro Apex One Server [CVE-2026-34926]
May 22, 2026
Deskripsi
1
| |
|
|
| |
Trend Micro mengungkap CVE-2026-34926, sebuah zero-day directory traversal pada Apex One (on-premises) yang menarget deployment Windows enterprise. Bulletin vendor diperbarui pada 21 Mei 2026 dan pada 22 Mei 2026 dilaporkan sudah ada upaya eksploitasi kerentanan ini, yang memungkinkan attacker lokal yang sudah memperoleh administrative credentials menyisipkan malicious code ke agent yang dikelola. Severity: High
|
|
| |
|
|
Metode Serangan
2
| |
|
|
| |
attacker yang sudah memiliki akses ke Apex One Server dan administrative credentials mengeksploitasi directory traversal untuk memodifikasi key table di server, lalu mendorong malicious code ke agent pada instalasi yang terdampak.
|
|
| |
|
|
Sistem Terdampak
3
| |
|
|
| |
Trend Micro Apex One 2019 (on-premises) di Windows, khususnya Server dan Agent build di bawah 17079. Vendor juga mencantumkan flaw agent terkait lain pada Apex One as a Service / TrendAI Vision One SEP dengan Agent build di bawah 14.0.20731, tetapi CVE-2026-34926 disebut hanya dapat dieksploitasi pada versi on-premises. (success.trendmicro.com)
|
|
| |
|
|
Mitigasi
4
| |
|
|
| |
- Update Apex One (on-premises) ke SP1 CP Build 18012 untuk existing SP1 users, atau minimal SP1 Build 17079 untuk instalasi baru.
- Terapkan patch dan update ke build terbaru sesegera mungkin pada seluruh server/agent terdampak.
- Review dan batasi remote access ke sistem kritis, serta pastikan kebijakan keamanan dan perimeter security tetap up to date.
|
|
| |
|
|
Referensi: ?
1. https://www.bleepingcomputer.com/news/security/trend-micro-warns-of-apex-one-zero-day-exploited-in-attacks/ (bleepingcomputer.com)