CVE-2025-49154 Details
Description
An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allow a local attacker to overwrite key memory-mapped files which could then have severe consequences for the security and stability of affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
A vulnerability allowing insecure access control has been identified in Trend Micro Apex One (2019 On-prem and SaaS) and Worry-Free Business Security (WFBS) 10.0 SP1, as well as Worry-Free Business Security Services (WFBSS) version 6.7. This vulnerability could enable a local attacker to overwrite critical memory-mapped files, potentially leading to severe security and stability issues on the affected systems. Exploitation requires the attacker to have the ability to execute low-privileged code on the target machine.
Users of Trend Micro Apex One can update to SP1 CP Build 14002, while those using Worry-Free Business Security should upgrade to WFBS 10 SP1 Patch 2514. For Worry-Free Business Security Services, the May 2025 Monthly Release (6.7.3954 / 14.3.1299) is available. Customers are encouraged to visit the Trend Micro Download Center for prerequisite software before applying these updates.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 17, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://success.trendmicro.com/en-US/solution/KA-0019917 | [email protected] | Vendor Advisory |
| https://success.trendmicro.com/en-US/solution/KA-0019936 | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-Other | Weakness Not in a Standard CWE Category | [email protected] |
| CWE-284 | Improper Access Control | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| trendmicro worry-free business security | 10.0 sp1 |
CPE
Remediation
| |
| trendmicro worry-free business security services | >= 6.7.0.0, < 6.7.3954 >= 14.0.0, < 14.3.1299 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
| trendmicro apex one | < 14.0.14492 >= 14.0.0.12994, < 14.0.0.14002 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Oct 6, 2025 | Initial Analysis | [email protected] |
| Jun 17, 2025 | New CVE Received | [email protected] |