Uncontrolled Search Path Vulnerability in Trend Micro Apex One Security Agent
CVE-2025-49158

6.7MEDIUM

What is CVE-2025-49158?

An uncontrolled search path vulnerability exists in the Trend Micro Apex One security agent, potentially allowing local attackers to escalate their privileges on affected installations. To exploit this vulnerability, an attacker would need to execute low-privileged code on the system prior to attempting the escalation.

Affected Version(s)

Trend Micro Apex One 2019 (14.0) < 14.0.0.14002

Trend Micro Apex One as a Service SaaS < 14.0.14492

References

CVSS V3.1

Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-49158 : Uncontrolled Search Path Vulnerability in Trend Micro Apex One Security Agent