An uncontrolled search path vulnerability in the Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an attacker with physical access to a machine to execute arbitrary code on affected installations. An attacker must have had physical access to the target system in order to exploit this vulnerability due to need to access a certain hardware component. Also note: this vulnerability only affected the SaaS client version of WFBSS only, meaning the on-premise version of Worry-Free Business Security was not affected, and this issue was addressed in a previous WFBSS monthly maintenance update. Therefore no other customer action is required to mitigate if the WFBSS agents are on the regular SaaS maintenance deployment schedule and this disclosure is for informational purposes only.
History

Tue, 17 Jun 2025 20:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 17 Jun 2025 19:00:00 +0000

Type Values Removed Values Added
Description An uncontrolled search path vulnerability in the Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an attacker with physical access to a machine to execute arbitrary code on affected installations. An attacker must have had physical access to the target system in order to exploit this vulnerability due to need to access a certain hardware component. Also note: this vulnerability only affected the SaaS client version of WFBSS only, meaning the on-premise version of Worry-Free Business Security was not affected, and this issue was addressed in a previous WFBSS monthly maintenance update. Therefore no other customer action is required to mitigate if the WFBSS agents are on the regular SaaS maintenance deployment schedule and this disclosure is for informational purposes only.
First Time appeared Trendmicro
Trendmicro wfbs Saas
Weaknesses CWE-427
CPEs cpe:2.3:a:trendmicro:wfbs_saas:20240325:ga:*:*:*:*:*:*
Vendors & Products Trendmicro
Trendmicro wfbs Saas
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: trendmicro

Published: 2025-06-17T18:43:11.176Z

Updated: 2025-06-17T19:52:40.992Z

Reserved: 2025-06-05T14:08:10.764Z

Link: CVE-2025-49487

cve-icon Vulnrichment

Updated: 2025-06-17T19:52:31.706Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-06-17T19:15:34.180

Modified: 2025-06-17T20:50:23.507

Link: CVE-2025-49487

cve-icon Redhat

No data.