Trend Micro Apex Central
cpe:2.3:a:trendmicro:apex_central:*:*:*:*:windows:*:*
- 2019 < build 6955
A Local File Inclusion vulnerability has been identified in Trend Micro Apex Central widgets prior to version 8.0.6955. This vulnerability could allow an attacker to execute arbitrary code on affected installations. The issue arises from improper validation of user-supplied data, which can be exploited by manipulating certain parameters. Authentication is required to exploit this vulnerability.
Exploitation of this vulnerability allows for remote code execution on the affected system, with the executed code running in the context of the IUSR account.
Users can update to Trend Micro Apex Central version 8.0.6955 or later. For the SaaS version, the March 2025 Monthly Maintenance Release is available. Instructions for downloading the on-premise version can be found on the Trend Micro Download Center.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.