CVE-2025-49155

An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code leading to arbitrary code execution on affected installations.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:trendmicro:apex_one:*:*:*:*:saas:windows:*:*
cpe:2.3:a:trendmicro:apex_one:*:*:*:*:on-premises:windows:*:*

History

09 Sep 2025, 15:24

Type Values Removed Values Added
CPE cpe:2.3:a:trendmicro:apex_one:*:*:*:*:saas:windows:*:*
cpe:2.3:a:trendmicro:apex_one:*:*:*:*:on-premises:windows:*:*
References () https://success.trendmicro.com/en-US/solution/KA-0019917 - () https://success.trendmicro.com/en-US/solution/KA-0019917 - Vendor Advisory
References () https://www.zerodayinitiative.com/advisories/ZDI-25-362/ - () https://www.zerodayinitiative.com/advisories/ZDI-25-362/ - Third Party Advisory
First Time Trendmicro
Trendmicro apex One

17 Jun 2025, 20:50

Type Values Removed Values Added
New CVE

Information

Published : 2025-06-17 19:15

Updated : 2025-09-09 15:24


NVD link : CVE-2025-49155

Mitre link : CVE-2025-49155

CVE.ORG link : CVE-2025-49155


JSON object : View

Products Affected

trendmicro

  • apex_one
CWE
CWE-427

Uncontrolled Search Path Element