CVE-2025-53378

Severity
9.8CRITICAL
EPSS
0.1%
top 68.71%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 10

Description

A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticated attacker to remotely take control of the agent on affected installations. Also note: this vulnerability only affected the SaaS client version of WFBSS only, meaning the on-premise version of Worry-Free Business Security was not affected, and this issue was addressed in a WFBSS monthly maintenance update. Therefore no other customer action is required to

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:HExploitability: 2.8 | Impact: 4.7

Affected Packages2 packages

🔴Vulnerability Details

2
GHSA
GHSA-57q3-g47v-6hpr: A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticated attack2025-07-10
CVEList
CVE-2025-53378: A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticated attack2025-07-10
CVE-2025-53378 (CRITICAL CVSS 9.8) | A missing authentication vulnerabil | cvebase.io