CVE Vulnerabilities

CVE-2025-47865

Undefined Behavior for Input to API

Published: Jun 17, 2025 | Modified: Sep 08, 2025
CVSS 3.x
9.8
CRITICAL
Source:
NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to gain remote code execution on affected installations.

Weakness

The behavior of this function is undefined unless its control parameter is set to a specific value.

Affected Software

NameVendorStart VersionEnd Version
Apex_centralTrendmicro2019 (including)2019 (including)
Apex_centralTrendmicro2019-build_3752 (including)2019-build_3752 (including)
Apex_centralTrendmicro2019-build_5158 (including)2019-build_5158 (including)
Apex_centralTrendmicro2019-build_6016 (including)2019-build_6016 (including)
Apex_centralTrendmicro2019-build_6288 (including)2019-build_6288 (including)
Apex_centralTrendmicro2019-build_6394 (including)2019-build_6394 (including)
Apex_centralTrendmicro2019-build_6481 (including)2019-build_6481 (including)
Apex_centralTrendmicro2019-build_6511 (including)2019-build_6511 (including)
Apex_centralTrendmicro2019-build_6571 (including)2019-build_6571 (including)
Apex_centralTrendmicro2019-build_6658 (including)2019-build_6658 (including)
Apex_centralTrendmicro2019-build_6660 (including)2019-build_6660 (including)
Apex_centralTrendmicro2019-build_6890 (including)2019-build_6890 (including)

References