Local Privilege Escalation Vulnerability in Trend Micro Apex One
CVE-2025-49156
7HIGH
Key Information:
- Vendor
Trend Micro
- Vendor
- CVE Published:
- 17 June 2025
What is CVE-2025-49156?
A vulnerability in the Trend Micro Apex One scan engine allows a local attacker to escalate privileges on affected systems. To exploit this vulnerability, an attacker must first execute low-privileged code on the system, which can lead to unauthorized access and control over sensitive functions or data. It’s imperative for organizations using Apex One to apply the necessary security updates to mitigate this risk and maintain system integrity.
Affected Version(s)
Trend Micro Apex One 2019 (14.0) < 14.0.0.14002
Trend Micro Apex One as a Service SaaS < 14.0.14492