CVE-2025-49154

An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allow a local attacker to overwrite key memory-mapped files which could then have severe consequences for the security and stability of affected installations.

Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.7 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H
trendmicroCNA
8.7 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 3%
VendorProductVersion
trendmicroworry-free_business_security
10.0:sp1
trendmicroworry-free_business_security
10.0:sp1
trendmicroworry-free_business_security_services
6.7.0.0 ≤
𝑥
< 6.7.3954
trendmicroworry-free_business_security_services
14.0.0 ≤
𝑥
< 14.3.1299
trendmicroapex_one
𝑥
< 14.0.14492
trendmicroapex_one
14.0.0.12994 ≤
𝑥
< 14.0.0.14002
𝑥
= Vulnerable software versions