{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-09-22T09:43:57.422","vulnerabilities":[{"cve":{"id":"CVE-2025-49154","sourceIdentifier":"security@trendmicro.com","published":"2025-06-17T19:15:33.010","lastModified":"2026-06-17T09:30:50.417","vulnStatus":"Analyzed","cveTags":[],"descriptions":[{"lang":"en","value":"An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allow a local attacker to overwrite key memory-mapped files which could then have severe consequences for the security and stability of affected installations.\r\n\r\nPlease note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability."},{"lang":"es","value":"Una vulnerabilidad de control de acceso inseguro en Trend Micro Apex One y Trend Micro Worry-Free Business Security podría permitir que un atacante local sobrescriba archivos clave asignados a memoria, lo que podría tener graves consecuencias para la seguridad y la estabilidad de las instalaciones afectadas. Nota: Para explotar esta vulnerabilidad, un atacante primero debe poder ejecutar código con privilegios bajos en el sistema objetivo."}],"affected":[{"source":"security@trendmicro.com","affectedData":[{"vendor":"Trend Micro, Inc.","product":"Trend Micro Apex One","cpes":["cpe:2.3:a:trendmicro:apexone_op:14.0.0.14002:p3:*:*:*:*:*:*"],"versions":[{"version":"2019 (14.0)","lessThan":"14.0.0.14002","versionType":"semver","status":"affected"}]},{"vendor":"Trend Micro, Inc.","product":"Trend Micro Apex One as a Service","cpes":["cpe:2.3:a:trendmicro:apexone_saas:14.0.0.14492:ga:*:*:*:*:*:*"],"versions":[{"version":"SaaS","lessThan":"14.0.14492","versionType":"semver","status":"affected"}]},{"vendor":"Trend Micro, Inc.","product":"Worry-Free Business Security","versions":[{"version":"10.0 SP1","lessThan":"2514","versionType":"semver","status":"affected"}]}]}],"metrics":{"cvssMetricV31":[{"source":"security@trendmicro.com","type":"Secondary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:H/A:H","baseScore":8.7,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"CHANGED","confidentialityImpact":"LOW","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":2.0,"impactScore":6.0},{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","baseScore":7.8,"baseSeverity":"HIGH","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"LOW","userInteraction":"NONE","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"HIGH","availabilityImpact":"HIGH"},"exploitabilityScore":1.8,"impactScore":5.9}],"ssvcV203":[{"source":"134c704f-9b21-4f2e-91b3-4a467353bcc0","ssvcData":{"timestamp":"2025-06-17T20:23:50.312099Z","id":"CVE-2025-49154","options":[{"exploitation":"none"},{"automatable":"no"},{"technicalImpact":"partial"}],"role":"CISA Coordinator","version":"2.0.3"}}]},"weaknesses":[{"source":"security@trendmicro.com","type":"Secondary","description":[{"lang":"en","value":"CWE-284"}]},{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"NVD-CWE-Other"}]}],"configurations":[{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:trendmicro:worry-free_business_security:10.0:sp1:*:*:advanced:*:*:*","matchCriteriaId":"F574A74D-1BA6-4231-8EE9-A75EE1348A6A"},{"vulnerable":true,"criteria":"cpe:2.3:a:trendmicro:worry-free_business_security:10.0:sp1:*:*:standard:*:*:*","matchCriteriaId":"4F5CDE90-9829-448B-B94C-5105C70484CD"},{"vulnerable":true,"criteria":"cpe:2.3:a:trendmicro:worry-free_business_security_services:*:*:*:*:saas:*:*:*","versionStartIncluding":"6.7.0.0","versionEndExcluding":"6.7.3954","matchCriteriaId":"661DB84A-9A36-4297-9ED9-211C222EEB80"},{"vulnerable":true,"criteria":"cpe:2.3:a:trendmicro:worry-free_business_security_services:*:*:*:*:saas:*:*:*","versionStartIncluding":"14.0.0","versionEndExcluding":"14.3.1299","matchCriteriaId":"0BDE03F7-BC04-48CA-B03B-893489B41F5F"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]},{"operator":"AND","nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:trendmicro:apex_one:*:*:*:*:saas:windows:*:*","versionEndExcluding":"14.0.14492","matchCriteriaId":"E2378C4C-B4CE-42E6-A506-2AF1B894E421"},{"vulnerable":true,"criteria":"cpe:2.3:a:trendmicro:apex_one:*:*:*:*:on-premises:windows:*:*","versionStartIncluding":"14.0.0.12994","versionEndExcluding":"14.0.0.14002","matchCriteriaId":"2C42CC6D-7812-4564-8002-3E1208E603B8"}]},{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":false,"criteria":"cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*","matchCriteriaId":"A2572D17-1DE6-457B-99CC-64AFD54487EA"}]}]}],"references":[{"url":"https://success.trendmicro.com/en-US/solution/KA-0019917","source":"security@trendmicro.com","tags":["Vendor Advisory"]},{"url":"https://success.trendmicro.com/en-US/solution/KA-0019936","source":"security@trendmicro.com","tags":["Vendor Advisory"]}]}}]}