Local File Inclusion Vulnerability in Trend Micro Apex Central Widget
CVE-2025-47867

7.5HIGH

Key Information:

Vendor
CVE Published:
17 June 2025

What is CVE-2025-47867?

A vulnerability exists within the Trend Micro Apex Central widget which allows local file inclusion. This flaw can be exploited by an attacker to include arbitrary files within the application. If successfully manipulated, this may lead to the execution of PHP code, potentially facilitating remote code execution on compromised systems. Users of versions prior to 8.0.6955 are particularly at risk, necessitating urgent measures to apply patches and secure their installations against this exploit.

Affected Version(s)

Trend Micro Apex Central 8.0 < 8.0.6955

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.