IT

Tracker / CVE-2025-49154

CVE-2025-49154

High 8.7

An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allow a local attacker to overwrite key memory-mapped files which could then have severe consequences for the security and stability of affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

Affected products and versions

trendmicro apex_one · … → 14.0.14492
trendmicro apex_one · 14.0.0.12994 → 14.0.0.14002
trendmicro worry-free_business_security
trendmicro worry-free_business_security_services · 14.0.0 → 14.3.1299
trendmicro worry-free_business_security_services · 6.7.0.0 → 6.7.3954

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References