Trend Micro Apex One and Worry-Free Business Security Insecure Access Control Vulnerability

Vulnerability

A vulnerability allowing insecure access control has been identified in Trend Micro Apex One (2019 On-prem and SaaS) and Worry-Free Business Security (WFBS) 10.0 SP1, as well as Worry-Free Business Security Services (WFBSS) version 6.7. This vulnerability could enable a local attacker to overwrite critical memory-mapped files, potentially leading to severe security and stability issues on the affected systems. Exploitation requires the attacker to have the ability to execute low-privileged code on the target machine.

Impact

Successful exploitation could allow a local attacker to overwrite key memory-mapped files, with serious implications for the security and stability of the affected installation.

Remediation

Users of Trend Micro Apex One can update to SP1 CP Build 14002, while those using Worry-Free Business Security should upgrade to WFBS 10 SP1 Patch 2514. For Worry-Free Business Security Services, the May 2025 Monthly Release (6.7.3954 / 14.3.1299) is available. Customers are encouraged to visit the Trend Micro Download Center for prerequisite software before applying these updates.

Added: Jun 17, 2025, 7:30 PM
Updated: Jun 17, 2025, 9:13 PM

Vulnerability Rating

Custom Algorithm
spread
6.8
impact
1.3
exploitability
3.5
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.