PT-2025-22432 · Trend Micro · Trend Micro Apex Central

Poh Jia Hao

·

Published

2024-10-03

·

Updated

2025-09-08

·

CVE-2025-47867

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Trend Micro Apex Central (affected versions not specified)
Description The issue is related to the getBlock() function in Trend Micro Apex Central's security monitoring and management tool, which fails to neutralize special elements in its output. This can be exploited by a remote attacker to execute arbitrary code.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

RCE

Special Elements Injection

Weakness Enumeration

Related Identifiers

BDU:2025-06034
CVE-2025-47867
ZDI-25-297

Affected Products

Trend Micro Apex Central