CVE-2023-25147
CVE-2023-25147
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 6.7EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
07 Mar 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
An issue in the Trend Micro Apex One agent could allow an attacker who has previously acquired administrative rights via other means to bypass the protection by using a specifically crafted DLL during a specific update process.
Please note: an attacker must first obtain administrative access on the target system via another method in order to exploit this.
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Affected products
Trend Micro, Inc. · Trend Micro Apex OneWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →