An issue in the Trend Micro Apex One agent could allow an attacker who has previously acquired administrative rights via other means to bypass the protection by using a specifically crafted DLL during a specific update process.

Please note: an attacker must first obtain administrative access on the target system via another method in order to exploit this.
Advisories
Source ID Title
EUVD EUVD EUVD-2023-29125 An issue in the Trend Micro Apex One agent could allow an attacker who has previously acquired administrative rights via other means to bypass the protection by using a specifically crafted DLL during a specific update process. Please note: an attacker must first obtain administrative access on the target system via another method in order to exploit this.
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 05 Mar 2025 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: trendmicro

Published:

Updated: 2025-03-05T20:43:49.976Z

Reserved: 2023-02-03T15:46:02.643Z

Link: CVE-2023-25147

cve-icon Vulnrichment

Updated: 2024-08-02T11:18:35.853Z

cve-icon NVD

Status : Modified

Published: 2023-03-10T21:15:15.203

Modified: 2025-03-05T21:15:17.313

Link: CVE-2023-25147

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.