9.8

CVE-2025-69258

Exploit
A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of attacker-supplied code under the context of SYSTEM on affected installations.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Apex Central Version 2019 Update - SwEdition -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex Central Version 2019 Update build_3752 SwEdition -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex Central Version 2019 Update build_5158 SwEdition -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex Central Version 2019 Update build_6016 SwEdition -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex Central Version 2019 Update build_6288 SwEdition -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex Central Version 2019 Update build_6394 SwEdition -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex Central Version 2019 Update build_6481 SwEdition -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex Central Version 2019 Update build_6511 SwEdition -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex Central Version 2019 Update build_6571 SwEdition -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex Central Version 2019 Update build_6658 SwEdition -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex Central Version 2019 Update build_6660 SwEdition -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex Central Version 2019 Update build_6890 SwEdition -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex Central Version 2019 Update build_6955 SwEdition -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex Central Version 2019 Update build_7007 SwEdition -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex Central Version 2019 Update build_7065 SwEdition -
   Microsoft ≫ Windows Version -
Trendmicro ≫ Apex Central Version 2019 Update build_7141 SwEdition -
   Microsoft ≫ Windows Version -
VulnDex Vulnerability Enrichment
Diese Information steht angemeldeten Benutzern zur Verfügung. Login Login
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 3.53% 0.881
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
Trendmicro 9.8 3.9 5.9
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')

The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.

CWE-290 Authentication Bypass by Spoofing

This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.

CWE-346 Origin Validation Error

The product does not properly verify that the source of data or communication is valid.

https://www.tenable.com/security/research/tra-2026-01
Third Party Advisory
Exploit
https://success.trendmicro.com/en-US/solution/KA-0022071
Vendor Advisory
https://success.trendmicro.com/ja-JP/solution/KA-0022081
Vendor Advisory