An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allow a local attacker to overwrite key memory-mapped files which could then have severe consequences for the security and stability of affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
2025-06-17T19:15:33.010
2025-10-06T19:11:24.100
Analyzed
CVSSv3.1: 8.7 (HIGH)
| Type | Vendor | Product | Version/Range | Vulnerable? |
|---|---|---|---|---|
| Application | trendmicro | worry-free_business_security | 10.0 | Yes |
| Application | trendmicro | worry-free_business_security | 10.0 | Yes |
| Application | trendmicro | worry-free_business_security_services | < 6.7.3954 | Yes |
| Application | trendmicro | worry-free_business_security_services | < 14.3.1299 | Yes |
| Operating System | microsoft | windows | - | No |
| Application | trendmicro | apex_one | < 14.0.14492 | Yes |
| Application | trendmicro | apex_one | < 14.0.0.14002 | Yes |
| Operating System | microsoft | windows | - | No |