CVE-2019-9489: Trend Micro Apex One

High severity, CVSS 7.5. EPSS: 2.3% chance of exploitation in the next 30 days.

A directory traversal vulnerability in Trend Micro Apex One, OfficeScan (versions XG and 11.0), and Worry-Free Business Security (versions 10.0, 9.5 and 9.0) could allow an attacker to modify arbitrary files on the affected product's management console.

Affected products

  • Trend Micro Apex One: up to and including b1066
  • Trend Micro Apex One As A Service: before 2019-03-27 (fixed in 2019-03-27)
  • Trend Micro Business Security: version 9.0 only
  • Trend Micro OfficeScan: version 11.0 only; version xg only
  • Trend Micro Worry-Free Business Security: version 9.5 only; version 10.0 only

Published 2019-04-05. Last modified 2026-06-17.