An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code leading to arbitrary code execution on affected installations.
                
            References
                    | Link | Resource | 
|---|---|
| https://success.trendmicro.com/en-US/solution/KA-0019917 | Vendor Advisory | 
| https://www.zerodayinitiative.com/advisories/ZDI-25-362/ | Third Party Advisory | 
Configurations
                    Configuration 1 (hide)
| 
 | 
History
                    09 Sep 2025, 15:24
| Type | Values Removed | Values Added | 
|---|---|---|
| Summary | 
 | |
| CPE | cpe:2.3:a:trendmicro:apex_one:*:*:*:*:saas:windows:*:* cpe:2.3:a:trendmicro:apex_one:*:*:*:*:on-premises:windows:*:* | |
| First Time | Trendmicro Trendmicro apex One | |
| References | () https://success.trendmicro.com/en-US/solution/KA-0019917 - Vendor Advisory | |
| References | () https://www.zerodayinitiative.com/advisories/ZDI-25-362/ - Third Party Advisory | 
17 Jun 2025, 19:15
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2025-06-17 19:15
Updated : 2025-09-09 15:24
NVD link : CVE-2025-49155
Mitre link : CVE-2025-49155
CVE.ORG link : CVE-2025-49155
JSON object : View
Products Affected
                trendmicro
- apex_one
CWE
                
                    
                        
                        CWE-427
                        
            Uncontrolled Search Path Element
