CVE-2023-25146
- EPSS 0.05%
- Veröffentlicht 10.03.2023 21:15:15
- Zuletzt bearbeitet 05.03.2025 21:15:17
A security agent link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to quarantine a file, delete the original folder and replace with a junction to an arbitrary location, ultimately leading to an arbitrary fil...
CVE-2023-25147
- EPSS 0.01%
- Veröffentlicht 10.03.2023 21:15:15
- Zuletzt bearbeitet 05.03.2025 21:15:17
An issue in the Trend Micro Apex One agent could allow an attacker who has previously acquired administrative rights via other means to bypass the protection by using a specifically crafted DLL during a specific update process. Please note: an att...
CVE-2023-25148
- EPSS 0.05%
- Veröffentlicht 10.03.2023 21:15:15
- Zuletzt bearbeitet 05.03.2025 21:15:17
A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to exploit the vulnerability by changing a specific file into a pseudo-symlink, allowing privilege escalation on affected installations. Please note...
CVE-2023-25143
- EPSS 5.82%
- Veröffentlicht 10.03.2023 21:15:14
- Zuletzt bearbeitet 05.03.2025 15:15:12
An uncontrolled search path element vulnerability in the Trend Micro Apex One Server installer could allow an attacker to achieve a remote code execution state on affected products.
CVE-2023-25144
- EPSS 0.07%
- Veröffentlicht 10.03.2023 21:15:14
- Zuletzt bearbeitet 06.03.2025 16:15:40
An improper access control vulnerability in the Trend Micro Apex One agent could allow a local attacker to gain elevated privileges and create arbitrary directories with arbitrary ownership.
CVE-2023-0587
- EPSS 31.84%
- Veröffentlicht 01.02.2023 03:15:08
- Zuletzt bearbeitet 27.03.2025 15:15:42
A file upload vulnerability in exists in Trend Micro Apex One server build 11110. Using a malformed Content-Length header in an HTTP PUT message sent to URL /officescan/console/html/cgi/fcgiOfcDDA.exe, an unauthenticated remote attacker can upload ar...
CVE-2022-45798
- EPSS 0.07%
- Veröffentlicht 24.12.2022 00:15:08
- Zuletzt bearbeitet 15.04.2025 14:15:37
A link following vulnerability in the Damage Cleanup Engine component of Trend Micro Apex One and Trend Micro Apex One as a Service could allow a local attacker to escalate privileges by creating a symbolic link and abusing the service to delete a fi...
CVE-2022-44647
- EPSS 0.09%
- Veröffentlicht 12.12.2022 13:15:15
- Zuletzt bearbeitet 29.04.2025 16:15:27
An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-p...
CVE-2022-44648
- EPSS 0.09%
- Veröffentlicht 12.12.2022 13:15:15
- Zuletzt bearbeitet 29.04.2025 05:15:45
An Out-of-bounds read vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to disclose sensitive information on affected installations. Please note: an attacker must first obtain the ability to execute low-p...
CVE-2022-44649
- EPSS 0.19%
- Veröffentlicht 12.12.2022 13:15:15
- Zuletzt bearbeitet 29.04.2025 05:15:45
An out-of-bounds access vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as a Service could allow a local attacker to elevate privileges on affected installations. Please note: an attacker must first...