CVE-2025-71212
7.8Trend Micro · Apex One
A link following vulnerability in the Trend Micro Apex One scan engine allows local attackers to escalate privileges on affected installations.
Executive summary
A link-following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalate privileges, leading to unauthorized system control.
Vulnerability
This is an improper link resolution vulnerability (CWE-59) that permits a local attacker with low privileges to manipulate file access paths to gain elevated permissions.
Business impact
Successful exploitation allows a local attacker to bypass security constraints, potentially gaining administrative access to the host. This high-severity issue (CVSS 7.8) could result in the total compromise of the affected machine, facilitating data theft or further malicious activity within the network.
Remediation
Immediate Action: Apply the vendor-provided security updates, upgrading to version 14.0.0.14136 or the equivalent SaaS version 14.0.20315.
Proactive Monitoring: Monitor for unusual file system activity or attempts to create symbolic links in directories used by the security agent.
Compensating Controls: Implement strict file system permissions to limit the ability of non-privileged users to interact with scan engine directories.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Immediate patching is required to address this privilege escalation risk. Organizations should ensure all endpoints running the affected versions are updated to the latest security baseline provided by Trend Micro.