vulnerability

Trend Micro Apex One: CVE-2023-25147: Uncontrolled Search Path Element

Severity
6
CVSS
(AV:L/AC:L/Au:M/C:C/I:C/A:C)
Published
Feb 9, 2023
Added
Apr 29, 2025
Modified
Jul 2, 2025

Description

An issue in the Trend Micro Apex One agent could allow an attacker who has previously acquired administrative rights via other means to bypass the protection by using a specifically crafted DLL during a specific update process.

Please note: an attacker must first obtain administrative access on the target system via another method in order to exploit this.

Solution

trend-micro-apex-one-upgrade-latest
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.