📦 Apex One

by Trendmicro

🔍 What is Apex One?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-54948

CRITICAL CVSS 9.4 Aug 5, 2025

A critical vulnerability in Trend Micro Apex One (on-premise) management console allows unauthenticated remote attackers to upload malicious code and execute arbitrary commands on affected systems. Th...

CVE-2023-32557

CRITICAL CVSS 9.8 Jun 26, 2023

This critical vulnerability allows unauthenticated attackers to upload arbitrary files to Trend Micro Apex One management servers via path traversal, potentially leading to remote code execution with ...

CVE-2023-25143

CRITICAL CVSS 9.8 Mar 10, 2023

This vulnerability in Trend Micro Apex One Server installer allows attackers to execute arbitrary code remotely by exploiting an uncontrolled search path element. Attackers can place malicious DLLs in...

CVE-2023-0587

CRITICAL CVSS 9.1 Feb 1, 2023

An unauthenticated remote file upload vulnerability in Trend Micro Apex One allows attackers to upload arbitrary files to the server's SampleSubmission directory. This can lead to denial of service by...

CVE-2022-26871

CRITICAL CVSS 9.8 Mar 29, 2022

CVE-2022-26871 is a critical arbitrary file upload vulnerability in Trend Micro Apex Central that allows unauthenticated remote attackers to upload malicious files to the server. This can lead to remo...

CVE-2024-58104

HIGH CVSS 7.3 Mar 25, 2025

This vulnerability in Trend Micro Apex One Security Agent allows a local attacker with low-privileged access to bypass security controls and execute arbitrary code on affected systems. It affects inst...

CVE-2024-58105

HIGH CVSS 7.3 Mar 25, 2025

This vulnerability in Trend Micro Apex One Security Agent Plug-in User Interface Manager allows a local attacker with low-privileged access to bypass security controls and execute arbitrary code on af...

CVE-2024-55917

HIGH CVSS 7.8 Dec 31, 2024

A local privilege escalation vulnerability in Trend Micro Apex One allows attackers with initial low-privileged access to gain elevated system privileges. This affects organizations using vulnerable v...

CVE-2024-55631

HIGH CVSS 7.8 Dec 31, 2024

This is a local privilege escalation vulnerability in Trend Micro Apex One security software. An attacker with existing low-privileged access on a system can exploit a link following flaw to gain elev...

CVE-2024-52048

HIGH CVSS 7.8 Dec 31, 2024

A local privilege escalation vulnerability in Trend Micro Apex One's LogServer component allows attackers who already have low-privileged access to elevate their privileges on affected systems. This l...

CVE-2024-52050

HIGH CVSS 7.8 Dec 31, 2024

This vulnerability in Trend Micro Apex One's LogServer component allows a local attacker with low-privileged code execution to create arbitrary files, potentially leading to privilege escalation. Affe...

CVE-2024-39753

HIGH CVSS 7.5 Oct 22, 2024

This is an SQL injection vulnerability in Trend Micro Apex One's modOSCE component that allows remote attackers to execute arbitrary code on affected systems. Attackers need low-privileged code execut...

CVE-2024-37289

HIGH CVSS 7.8 Jun 10, 2024

This vulnerability in Trend Micro Apex One allows a local attacker with low-privileged access to escalate privileges on affected systems. Attackers could gain administrative control over the endpoint ...

CVE-2024-36302

HIGH CVSS 7.8 Jun 10, 2024

This CVE describes an origin validation vulnerability in Trend Micro Apex One security agent that allows local attackers to escalate privileges on affected installations. Attackers must first gain low...

CVE-2024-36304

HIGH CVSS 7.8 Jun 10, 2024

A Time-of-Check Time-of-Use (TOCTOU) vulnerability in Trend Micro Apex One and Apex One as a Service agents allows local attackers to escalate privileges on affected systems. Attackers must first have...

CVE-2023-52090

HIGH CVSS 7.8 Jan 23, 2024

This CVE describes a link following vulnerability in Trend Micro Apex One security agent that allows a local attacker to escalate privileges on affected installations. An attacker must first have low-...

CVE-2023-52092

HIGH CVSS 7.8 Jan 23, 2024

This CVE describes a link following vulnerability in Trend Micro Apex One security agent that allows a local attacker to escalate privileges on affected installations. An attacker must first have low-...

CVE-2023-52094

HIGH CVSS 7.8 Jan 23, 2024

This vulnerability in Trend Micro Apex One agent allows a local attacker with low-privileged code execution to abuse the updater to delete arbitrary folders, potentially leading to local privilege esc...

CVE-2023-47193

HIGH CVSS 7.8 Jan 23, 2024

This CVE describes an origin validation vulnerability in Trend Micro Apex One security agent that allows a local attacker with low-privileged code execution to escalate privileges on affected installa...

CVE-2023-47195

HIGH CVSS 7.8 Jan 23, 2024

This CVE describes an origin validation vulnerability in Trend Micro Apex One security agent that allows a local attacker to escalate privileges on affected installations. Attackers must first gain lo...

CVE-2023-47197

HIGH CVSS 7.8 Jan 23, 2024

This CVE describes a local privilege escalation vulnerability in Trend Micro Apex One security agent where an attacker with low-privileged access can elevate privileges on affected systems. The vulner...

CVE-2023-47199

HIGH CVSS 7.8 Jan 23, 2024

This CVE describes an origin validation vulnerability in Trend Micro Apex One security agent that allows local attackers to escalate privileges on affected systems. Attackers must first gain low-privi...

CVE-2023-47201

HIGH CVSS 7.8 Jan 23, 2024

A local privilege escalation vulnerability in Trend Micro Apex One's plug-in manager allows attackers with initial low-privileged access to elevate their privileges on affected systems. This affects T...

CVE-2023-34144

HIGH CVSS 7.8 Jun 26, 2023

This is an untrusted search path vulnerability in Trend Micro Apex One and Apex One as a Service security agents that allows local attackers to escalate privileges on affected systems. Attackers must ...

CVE-2023-34146

HIGH CVSS 7.8 Jun 26, 2023

This vulnerability in Trend Micro Apex One and Apex One as a Service allows a local attacker with low-privileged code execution to escalate privileges and write arbitrary values to specific Trend Micr...

CVE-2023-34148

HIGH CVSS 7.8 Jun 26, 2023

This vulnerability in Trend Micro Apex One and Apex One as a Service allows a local attacker with low-privileged code execution to escalate privileges and write arbitrary values to specific Trend Micr...

CVE-2023-32554

HIGH CVSS 7.0 Jun 26, 2023

This CVE describes a Time-of-Check Time-of-Use (TOCTOU) vulnerability in Trend Micro Apex One and Apex One as a Service agents that allows local attackers to escalate privileges. Attackers must first ...

CVE-2023-25145

HIGH CVSS 7.8 Mar 10, 2023

This CVE describes a local privilege escalation vulnerability in Trend Micro Apex One's scanning function. An attacker with low-privileged access can exploit improper link following to gain elevated s...

CVE-2023-25148

HIGH CVSS 7.8 Mar 10, 2023

This vulnerability in Trend Micro Apex One allows a local attacker with low-privileged access to escalate privileges by manipulating file links. Attackers can change specific files into pseudo-symlink...

CVE-2022-30700

HIGH CVSS 7.8 May 27, 2022

This vulnerability allows a local attacker with existing low-privileged access to escalate privileges by loading a malicious DLL with incorrect permissions in Trend Micro Apex One products. It affects...

CVE-2022-24678

HIGH CVSS 7.5 Feb 24, 2022

This vulnerability allows attackers to flood temporary log locations in Trend Micro security agents, consuming all disk space and causing denial-of-service. Affected products include Trend Micro Apex ...

CVE-2022-24680

HIGH CVSS 7.8 Feb 24, 2022

This vulnerability allows a local attacker with low-privileged code execution to escalate privileges by creating mount points and deleting arbitrary folders in Trend Micro security products. Affected ...

CVE-2021-45441

HIGH CVSS 7.8 Jan 10, 2022

This vulnerability in Trend Micro Apex One allows a local attacker with initial low-privileged access to manipulate a specially crafted file and issue commands via a named pipe, leading to privilege e...

CVE-2021-23139

HIGH CVSS 7.5 Oct 21, 2021

A null pointer dereference vulnerability in Trend Micro Apex One and Worry-Free Business Security allows attackers to crash the CGI program on affected installations. This could lead to denial of serv...

CVE-2021-42012

HIGH CVSS 7.8 Oct 21, 2021

A stack-based buffer overflow vulnerability in Trend Micro Apex One and Worry-Free Business Security allows a local attacker with low-privileged code execution to escalate privileges on affected syste...

CVE-2021-42102

HIGH CVSS 7.8 Oct 21, 2021

This vulnerability allows a local attacker with low-privileged code execution to escalate privileges on Trend Micro Apex One installations. It affects both on-premise Apex One and cloud-based Apex One...

CVE-2021-42104

HIGH CVSS 7.8 Oct 21, 2021

This vulnerability allows a local attacker with low-privileged code execution on affected Trend Micro security products to escalate privileges to higher system levels. It affects Trend Micro Apex One,...

CVE-2021-42106

HIGH CVSS 7.8 Oct 21, 2021

This vulnerability allows a local attacker with low-privileged code execution on affected Trend Micro security products to escalate privileges to higher system levels. It affects Trend Micro Apex One,...

CVE-2021-42108

HIGH CVSS 7.8 Oct 21, 2021

This vulnerability allows a local attacker with low-privileged code execution on affected Trend Micro security products to escalate privileges via the Web Console. It affects Trend Micro Apex One, Ape...

CVE-2021-32464

HIGH CVSS 7.8 Aug 4, 2021

This vulnerability allows local privilege escalation in Trend Micro security products. An attacker with low-privileged code execution can modify scripts before they run to gain higher privileges. Affe...

CVE-2021-36741

HIGH CVSS 8.8 Jul 29, 2021

This vulnerability allows authenticated attackers to upload arbitrary files to Trend Micro security products due to improper input validation. Attackers must first obtain management console credential...

CVE-2021-32463

HIGH CVSS 7.8 Jul 20, 2021

This vulnerability allows a local attacker with low-privileged access to escalate privileges and delete files with system-level permissions on Trend Micro security products. It affects Trend Micro Ape...

CVE-2021-25253

HIGH CVSS 7.8 Apr 13, 2021

This vulnerability allows a local attacker with low-privileged access to escalate privileges on Trend Micro Apex One and OfficeScan XG SP1 installations. It affects Trend Micro Apex One, Apex One as a...

CVE-2021-25249

HIGH CVSS 7.8 Feb 4, 2021

This CVE describes an out-of-bounds write vulnerability in Trend Micro security products that allows a local attacker with low-privileged code execution to escalate privileges on affected systems. The...

CVE-2024-36306

MEDIUM CVSS 6.1 Jun 10, 2024

A link following vulnerability in Trend Micro Apex One and Apex One as a Service Damage Cleanup Engine allows a local attacker with low-privileged code execution to cause denial-of-service conditions ...