Actively Exploited in the Wild

This vulnerability is being actively exploited in the wild.

Trend Micro Apex One Command Injection Remote Code Execution Vulnerability

Vulnerability

A command injection vulnerability allowing pre-authenticated remote code execution has been identified in the Trend Micro Apex One (on-premise) management console, specifically in version 2019, Management Server Version 14039. This vulnerability arises from improper handling of user input, which could enable an attacker to upload malicious code and execute commands on the affected system.

Impact

Exploitation of this vulnerability allows for command injection, enabling remote execution of arbitrary commands on the affected system with the privileges of the Apex One management console.

Remediation

Trend Micro has released a short-term mitigation tool for this vulnerability, available as 'FixTool_Aug2025'. This tool protects against known exploits but temporarily disables the Remote Install Agent function. A formal Critical Patch is expected to be released in mid-August 2025, which will restore the Remote Install Agent functionality if applied after the FixTool.

Added: Aug 5, 2025, 1:20 PM
Updated: Aug 18, 2025, 2:07 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
10.0
exploitability
6.6
remediation
7.7
relevance
0.3
threat
8.2
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.