CVE-2023-25147

MEDIUM

Trend Micro Apex One - Uncontrolled Search Path Element via DLL Hijacking During Update

Title source: llm
STIX 2.1

Description

An issue in the Trend Micro Apex One agent could allow an attacker who has previously acquired administrative rights via other means to bypass the protection by using a specifically crafted DLL during a specific update process. Please note: an attacker must first obtain administrative access on the target system via another method in order to exploit this.

References (1)

Core 1
Core References

Scores

CVSS v3 6.7
EPSS 0.0006
EPSS Percentile 20.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-427
Status published
Products (2)
trendmicro/apex_one 2019
trendmicro/apex_one < 14.0.11960
Published Mar 10, 2023
Tracked Since Feb 18, 2026