A Local File Inclusion vulnerability in a Trend Micro Apex Central widget in versions below 8.0.6955 could allow an attacker to include arbitrary files to execute as PHP code and lead to remote code execution on affected installations.
References
Link | Resource |
---|---|
https://success.trendmicro.com/en-US/solution/KA-0019355 | Vendor Advisory |
https://www.zerodayinitiative.com/advisories/ZDI-25-297/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
08 Sep 2025, 21:04
Type | Values Removed | Values Added |
---|---|---|
References | () https://success.trendmicro.com/en-US/solution/KA-0019355 - Vendor Advisory | |
References | () https://www.zerodayinitiative.com/advisories/ZDI-25-297/ - Third Party Advisory | |
Summary |
|
|
First Time |
Microsoft
Microsoft windows Trendmicro Trendmicro apex Central |
|
CWE | NVD-CWE-noinfo | |
CPE | cpe:2.3:a:trendmicro:apex_central:2019:build_6016:*:*:-:*:*:* cpe:2.3:a:trendmicro:apex_central:2019:build_6658:*:*:-:*:*:* cpe:2.3:a:trendmicro:apex_central:2019:-:*:*:-:*:*:* cpe:2.3:a:trendmicro:apex_central:2019:build_6571:*:*:-:*:*:* cpe:2.3:a:trendmicro:apex_central:2019:build_5158:*:*:-:*:*:* cpe:2.3:a:trendmicro:apex_central:2019:build_3752:*:*:-:*:*:* cpe:2.3:a:trendmicro:apex_central:2019:build_6394:*:*:-:*:*:* cpe:2.3:a:trendmicro:apex_central:2019:build_6481:*:*:-:*:*:* cpe:2.3:a:trendmicro:apex_central:2019:build_6890:*:*:-:*:*:* cpe:2.3:a:trendmicro:apex_central:2019:build_6511:*:*:-:*:*:* cpe:2.3:a:trendmicro:apex_central:2019:build_6660:*:*:-:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:a:trendmicro:apex_central:2019:build_6288:*:*:-:*:*:* |
17 Jun 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-17 18:15
Updated : 2025-09-08 21:04
NVD link : CVE-2025-47867
Mitre link : CVE-2025-47867
CVE.ORG link : CVE-2025-47867
JSON object : View
Products Affected
trendmicro
- apex_central
microsoft
- windows
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
NVD-CWE-noinfo