9.8

CVE-2025-47867

A Local File Inclusion vulnerability in a Trend Micro Apex Central widget in versions below 8.0.6955 could allow an attacker to include arbitrary files to execute as PHP code and lead to remote code execution on affected installations.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Apex Central Version 2019 Update - SwEdition -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex Central Version 2019 Update build_3752 SwEdition -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex Central Version 2019 Update build_5158 SwEdition -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex Central Version 2019 Update build_6016 SwEdition -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex Central Version 2019 Update build_6288 SwEdition -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex Central Version 2019 Update build_6394 SwEdition -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex Central Version 2019 Update build_6481 SwEdition -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex Central Version 2019 Update build_6511 SwEdition -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex Central Version 2019 Update build_6571 SwEdition -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex Central Version 2019 Update build_6658 SwEdition -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex Central Version 2019 Update build_6660 SwEdition -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex Central Version 2019 Update build_6890 SwEdition -
   Microsoft ≫ Windows Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.64% 0.736
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Trendmicro 7.5 1.6 5.9
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CWE-74 Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

https://success.trendmicro.com/en-US/solution/KA-0019355
Vendor Advisory
https://www.zerodayinitiative.com/advisories/ZDI-25-297/
Third Party Advisory