SB2026022465 - Multiple vulnerabilities in Trend Micro Apex One for Windows
Published: February 24, 2026 Updated: March 4, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 4 vulnerabilities.
1) Origin validation error (CVE-ID: CVE-2025-71213)
CWE-ID: CWE-346 - Origin Validation Error
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to origin validation error. A local user can escalate privileges on the system.
2) Link following (CVE-ID: CVE-2025-71212)
CWE-ID: CWE-59 - Improper Link Resolution Before File Access ('Link Following')
CVSSv4: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to an insecure link following issue within the scan engine. A local user can create a specially crafted symbolic link to a critical file on the system and overwrite it with privileges of the application.
3) Path traversal (CVE-ID: CVE-2025-71211)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Red
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to input validation error when processing directory traversal sequences in the Trend Micro Apex One management console. A remote non-authenticated attacker can send a specially crafted HTTP request and read arbitrary files on the system.
Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.
4) Path traversal (CVE-ID: CVE-2025-71210)
CWE-ID: CWE-22 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVSSv4: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Red
The vulnerability allows a remote attacker to compromise the affected system.
The vulnerability exists due to input validation error when processing directory traversal sequences in the Trend Micro Apex One management console. A remote non-authenticated attacker can send a specially crafted HTTP request and read arbitrary files on the system.
Successful exploitation of the vulnerability may allow an attacker to compromise the affected system.
Remediation
Install update from vendor's website.