Trend Micro Apex Central 2019 Build 6016 and earlier contains two high-severity authenticated SQL injection vulnerabilities, CVE-2023-32529 and CVE-2023-32530, that can be escalated to remote code execution. The flaws affect the modTMMS certificate-handling workflow, where user-controlled X.509 certificate fields are incorporated into SQLite queries without proper validation, including the AddCert() and DeleteCertById() paths. Researchers said even low-privilege authenticated users can exploit the bugs by uploading crafted certificate data through proxy_controller.php, using module=modTMMS and tmms_cmd=set_certificates_config to reach the vulnerable functionality.
Because Apex Central uses SQLite on the backend, attackers can abuse the injection to write a malicious PHP file into the webroot and execute system commands as the IUSR account. Both issues carry a CVSS v3.1 score of 8.8 and were patched by Trend Micro on December 19, 2022, before public disclosure by STAR Labs and ZDI. Defenders are advised to update Apex Central to the latest available version and inspect the widget repository directory for suspicious PHP files that could indicate compromise.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
STAR Labs SG published advisories detailing two high-severity authenticated SQL injection vulnerabilities in Trend Micro Apex Central 2019. The disclosures explained that the bugs in the modTMMS certificate-handling workflow could be escalated to remote code execution and advised users to update and inspect for suspicious PHP files.
Trend Micro released fixes for two authenticated SQL injection vulnerabilities in Apex Central 2019 Build 6016 and earlier, later tracked as CVE-2023-32529 and CVE-2023-32530. Both flaws could be exploited by low-privilege authenticated users to achieve remote code execution by writing a PHP file into the webroot.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
starlabs.sg
Open sourcestarlabs.sg
Open sourcestarlabs.sg
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.