An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code leading to arbitrary code execution on affected installations.
Metrics
Affected Vendors & Products
References
History
Tue, 09 Sep 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Trendmicro apex One
|
|
CPEs | cpe:2.3:a:trendmicro:apex_one:*:*:*:*:on-premises:windows:*:* cpe:2.3:a:trendmicro:apex_one:*:*:*:*:saas:windows:*:* |
|
Vendors & Products |
Trendmicro apex One
|
Tue, 17 Jun 2025 21:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 17 Jun 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code leading to arbitrary code execution on affected installations. | |
First Time appeared |
Trendmicro
Trendmicro apexone Op Trendmicro apexone Saas |
|
Weaknesses | CWE-427 | |
CPEs | cpe:2.3:a:trendmicro:apexone_op:14.0.0.14002:p3:*:*:*:*:*:* cpe:2.3:a:trendmicro:apexone_saas:14.0.0.14492:ga:*:*:*:*:*:* |
|
Vendors & Products |
Trendmicro
Trendmicro apexone Op Trendmicro apexone Saas |
|
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: trendmicro
Published: 2025-06-17T18:42:31.517Z
Updated: 2025-06-17T20:22:40.129Z
Reserved: 2025-06-02T17:43:08.724Z
Link: CVE-2025-49155

Updated: 2025-06-17T20:22:34.788Z

Status : Analyzed
Published: 2025-06-17T19:15:33.130
Modified: 2025-09-09T15:24:13.320
Link: CVE-2025-49155

No data.