An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code leading to arbitrary code execution on affected installations.
References
| Link | Resource |
|---|---|
| https://success.trendmicro.com/en-US/solution/KA-0019917 | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-25-362/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
History
09 Sep 2025, 15:24
| Type | Values Removed | Values Added |
|---|---|---|
| Summary |
|
|
| CPE | cpe:2.3:a:trendmicro:apex_one:*:*:*:*:saas:windows:*:* cpe:2.3:a:trendmicro:apex_one:*:*:*:*:on-premises:windows:*:* |
|
| First Time |
Trendmicro
Trendmicro apex One |
|
| References | () https://success.trendmicro.com/en-US/solution/KA-0019917 - Vendor Advisory | |
| References | () https://www.zerodayinitiative.com/advisories/ZDI-25-362/ - Third Party Advisory |
17 Jun 2025, 19:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-06-17 19:15
Updated : 2025-09-09 15:24
NVD link : CVE-2025-49155
Mitre link : CVE-2025-49155
CVE.ORG link : CVE-2025-49155
JSON object : View
Products Affected
trendmicro
- apex_one
CWE
CWE-427
Uncontrolled Search Path Element
