Trendmicro Apex One vulnerabilities
173 known vulnerabilities affecting trendmicro/apex_one.
Total CVEs
173
CISA KEV
10
actively exploited
Public exploits
0
Exploited in wild
12
Severity breakdown
CRITICAL10HIGH116MEDIUM47
Vulnerabilities
Page 4 of 9
CVE-2020-24559P3HIGHCVSS 7.8v2019vsaas2020-09-01
CVE-2020-24559 [HIGH] CWE-59 CVE-2020-24559: A vulnerability in Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Busine
A vulnerability in Trend Micro Apex One, Worry-Free Business Security 10.0 SP1 and Worry-Free Business Security Services on macOS may allow an attacker to manipulate a certain binary to load and run a script from a user-writable folder, which then would allow them to execute arbitrary code as root. An attacker must first obtain the ability to execute l
nvd
CVE-2021-32464P3HIGHCVSS 7.8v20192021-08-04
CVE-2021-32464 [HIGH] CWE-276 CVE-2021-32464: An incorrect permission assignment privilege escalation vulnerability in Trend Micro Apex One, Apex
An incorrect permission assignment privilege escalation vulnerability in Trend Micro Apex One, Apex One as a Service and Worry-Free Business Security Services could allow an attacker to modify a specific script before it is executed. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to e
nvd
CVE-2022-44653P3HIGHCVSS 7.8fixed in 14.0.11789v20192022-12-12
CVE-2022-44653 [HIGH] CWE-22 CVE-2022-44653: A security agent directory traversal vulnerability in Trend Micro Apex One and Apex One as a Service
A security agent directory traversal vulnerability in Trend Micro Apex One and Apex One as a Service could allow a local attacker to escalate privileges on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
nvd
CVE-2021-25250P3HIGHCVSS 7.8v20192021-04-13
CVE-2021-25250 [HIGH] CWE-732 CVE-2021-25250: An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service
An improper access control vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service and OfficeScan XG SP1 on a sensitive file could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this v
nvd
CVE-2022-24680P3HIGHCVSS 7.8v20192022-02-24
CVE-2022-24680 [HIGH] CWE-59 CVE-2022-24680: A security link following local privilege escalation vulnerability in Trend Micro Apex One, Trend Mi
A security link following local privilege escalation vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-Free Business Security 10.0 SP1 and Trend Micro Worry-Free Business Security Services agents could allow a local attacker to create a mount point and leverage this for arbitrary folder deletion, leading to esc
nvd
CVE-2022-24679P3HIGHCVSS 7.8v20192022-02-24
CVE-2022-24679 [HIGH] CWE-59 CVE-2022-24679: A security link following local privilege escalation vulnerability in Trend Micro Apex One, Trend Mi
A security link following local privilege escalation vulnerability in Trend Micro Apex One, Trend Micro Apex One as a Service, Trend Micro Worry-Free Business Security 10.0 SP1 and Trend Micro Worry-Free Business Security Services agents could allow a local attacker to create an writable folder in an arbitrary location and escalate privileges affected
nvd
CVE-2023-25146P3HIGHCVSS 7.8fixed in 14.0.11960v20192023-03-10
CVE-2023-25146 [HIGH] CWE-59 CVE-2023-25146: A security agent link following vulnerability in the Trend Micro Apex One agent could allow a local
A security agent link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to quarantine a file, delete the original folder and replace with a junction to an arbitrary location, ultimately leading to an arbitrary file dropped to an arbitrary location.
Please note: an attacker must first obtain the ability to execute lo
nvd
CVE-2023-25148P3HIGHCVSS 7.8fixed in 14.0.11960v20192023-03-10
CVE-2023-25148 [HIGH] CWE-59 CVE-2023-25148: A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker t
A security agent link following vulnerability in Trend Micro Apex One could allow a local attacker to exploit the vulnerability by changing a specific file into a pseudo-symlink, allowing privilege escalation on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order t
nvd
CVE-2022-40141P3HIGHCVSS 7.5v20192022-09-19
CVE-2022-40141 [HIGH] CVE-2022-40141: A vulnerability in Trend Micro Apex One and Apex One as a Service could allow an attacker to interce
A vulnerability in Trend Micro Apex One and Apex One as a Service could allow an attacker to intercept and decode certain communication strings that may contain some identification attributes of a particular Apex One server.
nvd
CVE-2024-36303P3HIGHCVSS 7.8≥ 14.0, < 14.0.131392024-06-10
CVE-2024-36303 [HIGH] CVE-2024-36303: An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local at
An origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
This vulnerability is similar to, but not identical to,
nvd
CVE-2022-44649P3HIGHCVSS 7.8fixed in 14.0.11789v20192022-12-12
CVE-2022-44649 [HIGH] CWE-787 CVE-2022-44649: An out-of-bounds access vulnerability in the Unauthorized Change Prevention service of Trend Micro A
An out-of-bounds access vulnerability in the Unauthorized Change Prevention service of Trend Micro Apex One and Apex One as a Service could allow a local attacker to elevate privileges on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerab
nvd
CVE-2024-55917P3HIGHCVSS 7.8fixed in 14.0.14203fixed in 2019.131402024-12-31
CVE-2024-55917 [HIGH] CWE-346 CVE-2024-55917: An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to esc
An origin validation error vulnerability in Trend Micro Apex One could allow a local attacker to escalate privileges on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
nvd
CVE-2025-49157P3HIGHCVSS 7.8fixed in 14.0.14492≥ 14.0.0.12994, < 14.0.0.140022025-06-17
CVE-2025-49157 [HIGH] CWE-269 CVE-2025-49157: A link following vulnerability in the Trend Micro Apex One Damage Cleanup Engine could allow a local
A link following vulnerability in the Trend Micro Apex One Damage Cleanup Engine could allow a local attacker to escalation privileges on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
nvd
CVE-2023-47201P3HIGHCVSS 7.8fixed in 14.0.12737v20192024-01-23
CVE-2023-47201 [HIGH] CVE-2023-47201: A plug-in manager origin validation vulnerability in the Trend Micro Apex One security agent could a
A plug-in manager origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
This vulnerability is similar to, but no
nvd
CVE-2025-49158P3HIGHCVSS 7.8fixed in 14.0.14492≥ 14.0.0.12994, < 14.0.0.140022025-06-17
CVE-2025-49158 [HIGH] CWE-427 CVE-2025-49158: An uncontrolled search path vulnerability in the Trend Micro Apex One security agent could allow a l
An uncontrolled search path vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalation privileges on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
nvd
CVE-2025-49156P3HIGHCVSS 7.8fixed in 14.0.14492≥ 14.0.0.12994, < 14.0.0.140022025-06-17
CVE-2025-49156 [HIGH] CWE-269 CVE-2025-49156: A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker
A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalation privileges on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
nvd
CVE-2023-47200P3HIGHCVSS 7.8fixed in 14.0.12737v20192024-01-23
CVE-2023-47200 [HIGH] CWE-346 CVE-2023-47200: A plug-in manager origin validation vulnerability in the Trend Micro Apex One security agent could a
A plug-in manager origin validation vulnerability in the Trend Micro Apex One security agent could allow a local attacker to escalate privileges on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
This vulnerability is similar to
nvd
CVE-2020-25773P3HIGHCVSS 7.8v2019vsaas2020-09-29
CVE-2020-25773 [HIGH] CWE-415 CVE-2020-25773: A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to
A vulnerability in the Trend Micro Apex One ServerMigrationTool component could allow an attacker to execute arbitrary code on affected products. User interaction is required to exploit this vulnerability in that the target must import a corrupted configuration file.
nvd
CVE-2020-24556P3HIGHCVSS 7.8v2019vsaas2020-09-01
CVE-2020-24556 [HIGH] CWE-59 CVE-2020-24556: A vulnerability in Trend Micro Apex One, OfficeScan XG SP1, Worry-Free Business Security 10 SP1 and
A vulnerability in Trend Micro Apex One, OfficeScan XG SP1, Worry-Free Business Security 10 SP1 and Worry-Free Business Security Services on Microsoft Windows may allow an attacker to create a hard link to any file on the system, which then could be manipulated to gain a privilege escalation and code execution. An attacker must first obtain the ability
nvd
CVE-2022-36336P3HIGHCVSS 7.8v20192022-07-30
CVE-2022-36336 [HIGH] CWE-59 CVE-2022-36336: A link following vulnerability in the scanning function of Trend Micro Apex One and Worry-Free Busin
A link following vulnerability in the scanning function of Trend Micro Apex One and Worry-Free Business Security agents could allow a local attacker to escalate privileges on affected installations. The resolution for this issue has been deployed automatically via ActiveUpdate to customers in an updated Spyware pattern. Customers who are up-to-date on
nvd