Executive brief
Trend Micro Apex One is a centralized security management platform used to protect corporate endpoints. A vulnerability in its management console allows a remote attacker to upload malicious code and execute commands on the server without needing a username or password. This could lead to a complete takeover of the security management server and potential disruption of endpoint protections.
Technical details
A directory traversal vulnerability (CWE-22) exists in the Trend Micro Apex One management console due to improper validation of user-supplied strings before they are used in system calls. The flaw is located within a specific executable in the console, which typically listens on TCP ports 8080 and 4343. An unauthenticated remote attacker can exploit this by sending a specially crafted request to upload malicious code and execute it in the context of the IUSR account. Trend Micro has released Critical Patch Build 14136 for on-premises installations and has already mitigated the issue for SaaS customers.
Affected products
- Trend Micro Apex One 2019 (On-prem) Prior to CP Build 14136
- Trend Micro Apex One as a Service Prior to Security Agent Build 14.0.20315
- Trend Micro Trend Vision One Endpoint - Standard Endpoint Protection Prior to Security Agent Build 14.0.20315
Timeline
- 2025-09-11: disclosed: Vulnerability reported to vendor via Zero Day Initiative
- 2026-03-03: patched: Coordinated public release of advisory and patches
- 2026-05-21: advisory: NVD publication date