9.8
CVE-2025-69258
- EPSS 3.53%
- Veröffentlicht 08.01.2026 12:50:25
- Zuletzt bearbeitet 07.10.2026 09:10:00
- Erkennungen
A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of attacker-supplied code under the context of SYSTEM on affected installations.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Apex Central Version 2019 Update - SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_3752 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_5158 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6016 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6288 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6394 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6481 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6511 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6571 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6658 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6660 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6890 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_6955 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_7007 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_7065 SwEdition -
Trendmicro ≫ Apex Central Version 2019 Update build_7141 SwEdition -
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 3.53% | 0.881 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Trendmicro | 9.8 | 3.9 | 5.9 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
|
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
The product copies an input buffer to an output buffer without verifying that the size of the input buffer is less than the size of the output buffer.
CWE-290 Authentication Bypass by Spoofing
This attack-focused weakness is caused by incorrectly implemented authentication schemes that are subject to spoofing attacks.
CWE-346 Origin Validation Error
The product does not properly verify that the source of data or communication is valid.
https://www.tenable.com/security/research/tra-2026-01
https://success.trendmicro.com/en-US/solution/KA-0022071
https://success.trendmicro.com/ja-JP/solution/KA-0022081