A Local File Inclusion vulnerability in a Trend Micro Apex Central widget in versions below 8.0.6955 could allow an attacker to include arbitrary files to execute as PHP code and lead to remote code execution on affected installations.
References
Link | Resource |
---|---|
https://success.trendmicro.com/en-US/solution/KA-0019355 | Vendor Advisory |
https://www.zerodayinitiative.com/advisories/ZDI-25-297/ | Third Party Advisory |
Configurations
Configuration 1 (hide)
AND |
|
History
08 Sep 2025, 21:04
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
References | () https://success.trendmicro.com/en-US/solution/KA-0019355 - Vendor Advisory | |
References | () https://www.zerodayinitiative.com/advisories/ZDI-25-297/ - Third Party Advisory | |
First Time |
Microsoft windows
Trendmicro Microsoft Trendmicro apex Central |
|
CPE | cpe:2.3:a:trendmicro:apex_central:2019:build_6016:*:*:-:*:*:* cpe:2.3:a:trendmicro:apex_central:2019:build_6394:*:*:-:*:*:* cpe:2.3:a:trendmicro:apex_central:2019:build_6660:*:*:-:*:*:* cpe:2.3:a:trendmicro:apex_central:2019:build_6658:*:*:-:*:*:* cpe:2.3:a:trendmicro:apex_central:2019:build_3752:*:*:-:*:*:* cpe:2.3:a:trendmicro:apex_central:2019:build_6511:*:*:-:*:*:* cpe:2.3:a:trendmicro:apex_central:2019:build_5158:*:*:-:*:*:* cpe:2.3:a:trendmicro:apex_central:2019:build_6288:*:*:-:*:*:* cpe:2.3:a:trendmicro:apex_central:2019:build_6481:*:*:-:*:*:* cpe:2.3:a:trendmicro:apex_central:2019:build_6571:*:*:-:*:*:* cpe:2.3:a:trendmicro:apex_central:2019:build_6890:*:*:-:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:a:trendmicro:apex_central:2019:-:*:*:-:*:*:* |
|
CWE | NVD-CWE-noinfo |
17 Jun 2025, 18:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-06-17 18:15
Updated : 2025-09-08 21:04
NVD link : CVE-2025-47867
Mitre link : CVE-2025-47867
CVE.ORG link : CVE-2025-47867
JSON object : View
Products Affected
microsoft
- windows
trendmicro
- apex_central
CWE
CWE-74
Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
NVD-CWE-noinfo