A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.
A command injection vulnerability (CWE-78) in the management console allows an attacker to submit malicious code to the vulnerable installation without possessing any credentials. The submitted payload is subsequently executed in the context of the operating system on which the console runs. The attack vector is network-based, requires no user interaction or attacker-side privileges (AV:N/AC:L/PR:N/UI:N).
An attacker can obtain unauthorized access to sensitive data (including configuration and environment data), partially modify system resources, and cause service unavailability, collectively threatening the confidentiality, integrity, and availability of the protected environment.
Patches available from the vendor should be applied immediately according to references (https://success.trendmicro.com/en-US/solution/KA-0020652). Until updates are deployed, it is recommended to restrict network access to the management console to trusted hosts only and implement enhanced monitoring of logs for unauthorized requests.
Trend Micro Apex One on-premise version – detailed information on vulnerable versions available in vendor references (KA-0020652)
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:L/A:HTrendmicro Apex One
APPTrendmicro2019
CISA KEV — detailsi
- Vendori
- Trend Micro
- Producti
- Apex One
- Added to KEVi
- August 18, 2025
- Remediation deadline (US Federal)i
- September 8, 2025(overdue)
Apply mitigations per vendor instructions, follow applicable BOD 22-01 guidance for cloud services, or discontinue use of the product if mitigations are unavailable.
Trend Micro Apex One Management Console (on-premise) contains an OS command injection vulnerability that could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations.
Related vulnerabilities
Trend Micro Apex Central — dowolne przesyłanie plików prowadzące do RCE
Trend Micro Apex One / OfficeScan XG — zapis pliku bez uwierzytelnienia i bypass loginu ROOT
RCE w Trend Micro Apex One – command injection bez uwierzytelnienia
Path Traversal umożliwiający RCE w Trend Micro Apex One
RCE poprzez niekontrolowany element ścieżki wyszukiwania w instalatorze Trend Micro Apex One Server