CVE-2025-49155

An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code leading to arbitrary code execution on affected installations.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:trendmicro:apex_one:*:*:*:*:saas:windows:*:*
cpe:2.3:a:trendmicro:apex_one:*:*:*:*:on-premises:windows:*:*

History

09 Sep 2025, 15:24

Type Values Removed Values Added
Summary
  • (es) Una vulnerabilidad en la ruta de búsqueda no controlada en el módulo Trend Micro Apex One Data Loss Prevention podría permitir que un atacante inyecte código malicioso que provoque la ejecución de código arbitrario en las instalaciones afectadas.
References () https://success.trendmicro.com/en-US/solution/KA-0019917 - () https://success.trendmicro.com/en-US/solution/KA-0019917 - Vendor Advisory
References () https://www.zerodayinitiative.com/advisories/ZDI-25-362/ - () https://www.zerodayinitiative.com/advisories/ZDI-25-362/ - Third Party Advisory
CPE cpe:2.3:a:trendmicro:apex_one:*:*:*:*:saas:windows:*:*
cpe:2.3:a:trendmicro:apex_one:*:*:*:*:on-premises:windows:*:*
First Time Trendmicro apex One
Trendmicro

17 Jun 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-17 19:15

Updated : 2025-09-09 15:24


NVD link : CVE-2025-49155

Mitre link : CVE-2025-49155

CVE.ORG link : CVE-2025-49155


JSON object : View

Products Affected

trendmicro

  • apex_one
CWE
CWE-427

Uncontrolled Search Path Element