CVE-2025-49155
HIGHCVSS 8.8/10EPSS 0.79%
Last modified
CVE-2025-49155 is a high-severity vulnerability rated 8.8/10 on the CVSS scale. An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code leading to arbitrary code execution on affected installations.. EPSS estimates a 0.79% chance of exploitation in the next 30 days.
Description
An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code leading to arbitrary code execution on affected installations.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Trendmicro | Apex One | < 14.0.14492 |
| Trendmicro | Apex One | >= 14.0.0.12994, < 14.0.0.14002 |
References
- https://success.trendmicro.com/en-US/solution/KA-0019917Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-25-362/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-49155?
An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code leading to arbitrary code execution on affected installations.
How severe is CVE-2025-49155?
CVE-2025-49155 has a CVSS score of 8.8/10 (HIGH severity). The EPSS model estimates a 0.79% probability of exploitation in the next 30 days.
How do I fix CVE-2025-49155?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-4915A vulnerability was found in PHPGurukul Auto Taxi Stand Mana…9.8
- CVE-2025-49150Cursor is a code editor built for programming with AI. Prior…5.9
- CVE-2025-49151The affected products could allow an unauthenticated attacke…9.3
- CVE-2025-49152The affected products contain JSON Web Tokens (JWT) that do …8.7
- CVE-2025-49153The affected products could allow an unauthenticated attacke…9.3
- CVE-2025-49154An insecure access control vulnerability in Trend Micro Apex…7.8
- CVE-2025-49156A link following vulnerability in the Trend Micro Apex One s…7.8
- CVE-2025-49157A link following vulnerability in the Trend Micro Apex One D…7.8
- CVE-2025-49158An uncontrolled search path vulnerability in the Trend Micro…7.8
- CVE-2025-4916A vulnerability was found in PHPGurukul Auto Taxi Stand Mana…9.8
- CVE-2025-49162Arris VIP1113 devices through 2025-05-30 with KreaTV SDK all…6.4
- CVE-2025-49163Arris VIP1113 devices through 2025-05-30 with KreaTV SDK all…6.7
Are you affected by CVE-2025-49155?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
