7.8

CVE-2025-49154

An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allow a local attacker to overwrite key memory-mapped files which could then have severe consequences for the security and stability of affected installations.

Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Worry-free Business Security Version 10.0 Update sp1 SwEdition advanced
   Microsoft ≫ Windows Version -
Trendmicro ≫ Worry-free Business Security Version 10.0 Update sp1 SwEdition standard
   Microsoft ≫ Windows Version -
Trendmicro ≫ Worry-free Business Security Services SwEdition saas Version >= 6.7.0.0 < 6.7.3954
   Microsoft ≫ Windows Version -
Trendmicro ≫ Worry-free Business Security Services SwEdition saas Version >= 14.0.0 < 14.3.1299
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex One SwEdition saas SwPlatform windows Version < 14.0.14492
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex One SwEdition on-premises SwPlatform windows Version >= 14.0.0.12994 < 14.0.0.14002
   Microsoft ≫ Windows Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.11% 0.013
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Trendmicro 8.7 2 6
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H
CWE-284 Improper Access Control

The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

https://success.trendmicro.com/en-US/solution/KA-0019917
Vendor Advisory
https://success.trendmicro.com/en-US/solution/KA-0019936
Vendor Advisory