CVE-2025-69260
7.5Trend Micro · Apex Central
A message out-of-bounds read vulnerability in Trend Micro Apex Central allows an unauthenticated remote attacker to cause a denial-of-service condition on affected installations.
Executive summary
A critical out-of-bounds read vulnerability in Trend Micro Apex Central allows unauthenticated remote attackers to trigger a denial-of-service condition, potentially disrupting security management.
Vulnerability
The vulnerability is caused by an out-of-bounds read, classified under CWE-120 and CWE-346, which allows an unauthenticated remote attacker to send specially crafted messages to the application. This flaw impacts the availability of the system by forcing a crash or service interruption.
Business impact
Successful exploitation of this vulnerability results in a denial-of-service, which prevents administrators from managing security policies or monitoring network health via the Apex Central console. Given the CVSS score of 7.5, this high-severity flaw poses a significant risk to operational continuity, as attackers can remotely disable critical security infrastructure without requiring any prior authentication.
Remediation
Immediate Action: Update Trend Micro Apex Central to Build 7190 or later as specified in the official vendor advisory.
Proactive Monitoring: Monitor system logs and network traffic for unusual message patterns or repeated connection attempts directed at the Apex Central management interface.
Compensating Controls: Deploy Web Application Firewall (WAF) rules to filter malicious traffic and restrict access to the Apex Central management port to trusted internal IP addresses only.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
This vulnerability represents a significant risk to the availability of the Apex Central management platform. Organizations should prioritize applying the vendor-provided update to Build 7190 immediately to eliminate the risk of remote service disruption. Failure to patch leaves the management console exposed to unauthenticated attackers capable of impacting core security operations.