← Back

CVE-2025-71214

nvd nist
Published: May 21, 2026Modified: Jun 5, 2026

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: 134c704f-9b21-4f2e-91b3-4a467353bcc0 (Secondary)

Description

An origin validation error vulnerability in the Trend Micro Apex One (mac) agent iCore service could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The following information is provided as informational only for CVE references, as these were addressed already via ActiveUpdate/SaaS updates in mid to late 2025 (SaaS 2507 & 2005 Yearly Release).

Affected (2)

Products: Trendmicro: Apex One
1 product
Apex One
Configuration A
2 vulnerable
Vulnerable SoftwareAffected Versions
Trendmicro
All versions
All versions

References (2)

Source: security@trendmicro.com
Vendor Advisory
Source: security@trendmicro.com
Third Party Advisory

Timeline

No history available yet.