9.8
CVE-2025-47865
- EPSS 1.56%
- Veröffentlicht 17.06.2025 17:42:30
- Zuletzt bearbeitet 08.09.2025 21:04:46
- Erkennungen
A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to gain remote code execution on affected installations.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Apex Central Version 2019 Update - SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_3752 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_5158 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6016 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6288 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6394 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6481 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6511 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6571 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6658 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6660 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6890 SwEdition -
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 1.56% | 0.722 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
| Trendmicro | 7.5 | 1.6 | 5.9 |
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-475 Undefined Behavior for Input to API
The behavior of this function is undefined unless its control parameter is set to a specific value.
https://success.trendmicro.com/en-US/solution/KA-0019355
https://www.zerodayinitiative.com/advisories/ZDI-25-295/