CVE Vulnerabilities

CVE-2025-47865

Undefined Behavior for Input to API

Published: Jun 17, 2025 | Modified: Sep 08, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to gain remote code execution on affected installations.

Weakness

The behavior of this function is undefined unless its control parameter is set to a specific value.

Affected Software

Name Vendor Start Version End Version
Apex_central Trendmicro 2019 (including) 2019 (including)
Apex_central Trendmicro 2019-build_3752 (including) 2019-build_3752 (including)
Apex_central Trendmicro 2019-build_5158 (including) 2019-build_5158 (including)
Apex_central Trendmicro 2019-build_6016 (including) 2019-build_6016 (including)
Apex_central Trendmicro 2019-build_6288 (including) 2019-build_6288 (including)
Apex_central Trendmicro 2019-build_6394 (including) 2019-build_6394 (including)
Apex_central Trendmicro 2019-build_6481 (including) 2019-build_6481 (including)
Apex_central Trendmicro 2019-build_6511 (including) 2019-build_6511 (including)
Apex_central Trendmicro 2019-build_6571 (including) 2019-build_6571 (including)
Apex_central Trendmicro 2019-build_6658 (including) 2019-build_6658 (including)
Apex_central Trendmicro 2019-build_6660 (including) 2019-build_6660 (including)
Apex_central Trendmicro 2019-build_6890 (including) 2019-build_6890 (including)

References