CVE-2025-71212 Details
Description
A link following vulnerability in the Trend Micro Apex One scan engine could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
A local privilege escalation vulnerability has been identified in the Trend Micro Apex One scan engine. This vulnerability allows a local attacker to escalate privileges on affected installations by exploiting a link following flaw within the Virus Scan Engine. An attacker must first have the ability to execute low-privileged code on the target system to exploit this issue. The vulnerability exists in Trend Micro Apex One 2019 (On-prem) for Windows, as well as in Apex One as a Service and Trend Vision One Endpoint - Standard Endpoint Protection, both on Windows.
Trend Micro has released a Critical Patch for Apex One 2019 (On-prem) users, available for download from the Trend Micro Download Center. For Apex One as a Service and Trend Vision One Endpoint - Standard Endpoint Protection users, the update has been applied automatically.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 21, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://success.trendmicro.com/en-US/solution/KA-0022458 | [email protected] | Vendor Advisory |
| https://www.zerodayinitiative.com/advisories/ZDI-26-138/ | [email protected] | Third Party Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-59 | Improper Link Resolution Before File Access ('Link Following') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| trendmicro apex one | < 14.0.0.14136 < 14.0.20315 |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 22, 2026 | Initial Analysis | [email protected] |
| May 21, 2026 | New CVE Received | [email protected] |