Trend Micro Mobile Security (Enterprise) 9.8 SP5 through Critical Patch 3 contains two critical flaws, CVE-2023-32523 and CVE-2023-32524, that allow unauthenticated attackers to achieve pre-authenticated remote code execution by chaining an authentication bypass with unrestricted file upload and local file inclusion weaknesses. In both cases, the application trusts a user-controlled session_info cookie at the /widget endpoint, automatically creates missing WFUser accounts with blank passwords, and binds them to a valid PHP session, giving attackers authenticated access without valid credentials.
Attackers can then upload an arbitrary PHP file such as PoolManager.php into C:\Windows\Temp through proxy_controller.php and execute it via path traversal or unsanitized require_once input in widget_package_manager.php or widgetforsecurity_package_manager.php. The bugs are rated CVSS 9.8, require no authentication or user interaction, and could enable arbitrary code execution on the appliance and follow-on lateral movement. Trend Micro issued fixes on April 18, 2023, and defenders were advised to inspect C:\Windows\Temp for unexpected PHP files and review logs for suspicious requests hitting the vulnerable endpoints in close succession.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
On 2023-08-22, STAR Labs published advisories for CVE-2023-32523 and CVE-2023-32524, describing how user-controlled session cookies could create blank-password accounts and enable pre-authenticated RCE. The advisories also included exploitation details and detection guidance such as checking for suspicious PHP files in C:\Windows\Temp and reviewing requests to vulnerable endpoints.
Trend Micro released fixes on 2023-04-18 for two critical authentication bypass vulnerabilities in Mobile Security (Enterprise) 9.8 SP5 up to Critical Patch 3. The flaws could be chained with unrestricted file upload and local file inclusion issues to achieve unauthenticated remote code execution.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
starlabs.sg
Open sourcestarlabs.sg
Open sourcestarlabs.sg
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.