Uncontrolled Search Path Vulnerability in Trend Micro Apex One Security Agent
CVE-2025-49158
6.7MEDIUM
Key Information:
- Vendor
Trend Micro
- Vendor
- CVE Published:
- 17 June 2025
What is CVE-2025-49158?
An uncontrolled search path vulnerability exists in the Trend Micro Apex One security agent, potentially allowing local attackers to escalate their privileges on affected installations. To exploit this vulnerability, an attacker would need to execute low-privileged code on the system prior to attempting the escalation.
Affected Version(s)
Trend Micro Apex One 2019 (14.0) < 14.0.0.14002
Trend Micro Apex One as a Service SaaS < 14.0.14492
References
CVSS V3.1
Score:
6.7
Severity:
MEDIUM
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved