CVE-2023-25146: Trend Micro Apex One
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
A security agent link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to quarantine a file, delete the original folder and replace with a junction to an arbitrary location, ultimately leading to an arbitrary file dropped to an arbitrary location. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Affected products
- Trend Micro Apex One: before 14.0.11960 (fixed in 14.0.11960); version 2019 only
Published 2023-03-10. Last modified 2026-06-17.