HIGH🇬🇧 English

CVE-2024-58105

CVSS 7.3v3.1pub. 2025-03-25upd. 2025-08-01

A vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager could allow a local attacker to bypass existing security and execute arbitrary code on affected installations. This CVE address an addtional bypass not covered in CVE-2024-58104. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

oryginał EN
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
  • Trendmicro Apex One

    APP
    Trendmicro
    < 14.0.14203< 2019.13140
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
Tagi
RCE
CWE
Referencje

Powiązane podatności

CVE-2025-54948CRITICAL9.4⚠ KEVPL ✓ten sam produkt

Command injection w Trend Micro Apex One – RCE bez uwierzytelnienia

CVE-2022-26871CRITICAL9.8⚠ KEVPL ✓ten sam produkt

Trend Micro Apex Central — dowolne przesyłanie plików prowadzące do RCE

CVE-2020-8599CRITICAL9.8⚠ KEVPL ✓ten sam produkt

Trend Micro Apex One / OfficeScan XG — zapis pliku bez uwierzytelnienia i bypass loginu ROOT

CVE-2025-54987CRITICAL9.4PL ✓ten sam produkt

RCE w Trend Micro Apex One – command injection bez uwierzytelnienia

CVE-2023-32557CRITICAL9.8PL ✓ten sam produkt

Path Traversal umożliwiający RCE w Trend Micro Apex One