CVE Vulnerabilities

CVE-2024-58105

Incorrect User Management

Published: Mar 25, 2025 | Modified: Aug 01, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security and execute arbitrary code on affected installations.

This CVE address an addtional bypass not covered in CVE-2024-58104.

Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

Weakness

The product does not properly manage a user within its environment.

Affected Software

Name Vendor Start Version End Version
Apex_one Trendmicro * 14.0.14203 (excluding)
Apex_one Trendmicro * 2019.13140 (excluding)

References