An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code leading to arbitrary code execution on affected installations.
https://www.zerodayinitiative.com/advisories/ZDI-25-362/
https://success.trendmicro.com/en-US/solution/KA-0019917
Source: Mitre, NVD
Published: 2025-06-17
Updated: 2025-06-17
Base Score: 10
Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C
Severity: Critical
Base Score: 8.8
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Severity: High
EPSS: 0.00046