An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code leading to arbitrary code execution on affected installations.
References
Link | Resource |
---|---|
https://success.trendmicro.com/en-US/solution/KA-0019917 | Vendor Advisory |
https://www.zerodayinitiative.com/advisories/ZDI-25-362/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
09 Sep 2025, 15:24
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References | () https://success.trendmicro.com/en-US/solution/KA-0019917 - Vendor Advisory | |
References | () https://www.zerodayinitiative.com/advisories/ZDI-25-362/ - Third Party Advisory | |
CPE | cpe:2.3:a:trendmicro:apex_one:*:*:*:*:saas:windows:*:* cpe:2.3:a:trendmicro:apex_one:*:*:*:*:on-premises:windows:*:* |
|
First Time |
Trendmicro apex One
Trendmicro |
17 Jun 2025, 19:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-17 19:15
Updated : 2025-09-09 15:24
NVD link : CVE-2025-49155
Mitre link : CVE-2025-49155
CVE.ORG link : CVE-2025-49155
JSON object : View
Products Affected
trendmicro
- apex_one
CWE
CWE-427
Uncontrolled Search Path Element