CVE-2025-53378
Severity
9.8CRITICAL
EPSS
0.1%
top 68.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedJul 10
Description
A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticated attacker to remotely take control of the agent on affected installations.
Also note: this vulnerability only affected the SaaS client version of WFBSS only, meaning the on-premise version of Worry-Free Business Security was not affected, and this issue was addressed in a WFBSS monthly maintenance update. Therefore no other customer action is required to…
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:HExploitability: 2.8 | Impact: 4.7
Affected Packages2 packages
▶CVEListV5trend_micro,_inc./trend_micro_worry-free_business_security_servicesSaaS — 6.7.3954 / 14.3.1299
🔴Vulnerability Details
2GHSA▶
GHSA-57q3-g47v-6hpr: A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticated attack↗2025-07-10
CVEList▶
CVE-2025-53378: A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticated attack↗2025-07-10