Vulnerabilidades em Trend Micro, Inc.

180 resultados
Análise Vexday

O portfólio de vulnerabilidades da Trend Micro, Inc. reúne 180 CVEs catalogadas, das quais 3 estão confirmadas em exploração ativa no catálogo KEV da CISA — representando uma taxa 3,7 vezes acima da média geral do catálogo, sinal que merece atenção prioritária de equipes de resposta. A falha mais crítica em exploração ativa no momento é CVE-2025-54948, com pontuação EPSS de 0,2025, indicando probabilidade relevante de exploração continuada. O tipo de falha mais recorrente é CWE-346 (validação de origem em requisições), padrão que sugere fragilidades no controle de confiança entre componentes. Com 13 CVEs de severidade crítica, 16 surgidas nos últimos 90 dias e um EPSS máximo observado de 0,6894, o ritmo de novas exposições e o potencial de exploração justificam monitoramento contínuo e aplicação ágil de correções.

CVE-2023-32521A path traversal exists in a specific service dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an unauthenticated rEPSS 66.8%CVE-2025-54948CRITICALA vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious EPSS 20.8%KEVCVE-2025-54987CRITICALA vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious EPSS 17.1%CVE-2026-34926MEDIUMA directory traversal vulnerability in the Apex One (on-premise) server could allow a pre-authenticated local attacker to modify a key tableEPSS 12.7%KEVCVE-2025-49213CRITICALAn insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code exeEPSS 9.8%CVE-2025-49212CRITICALAn insecure deserialization operation in the Trend Micro Endpoint Encryption PolicyServer could lead to a pre-authentication remote code exeEPSS 9.8%CVE-2023-41179HIGHA vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security anEPSS 4.7%KEVCVE-2023-52325HIGHA local file inclusion vulnerability in one of Trend Micro Apex Central's widgets could allow a remote attacker to execute arbitrary code onEPSS 4.5%CVE-2023-52324HIGHAn unrestricted file upload vulnerability in Trend Micro Apex Central could allow a remote attacker to create arbitrary files on affected inEPSS 4.2%CVE-2024-51503HIGHA security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate pEPSS 4.0%CVE-2025-71210CRITICALA vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands oEPSS 3.8%CVE-2025-71211CRITICALA vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands oEPSS 3.8%CVE-2025-69258CRITICALA LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL EPSS 3.5%CVE-2023-32522A path traversal exists in a specific dll of Trend Micro Mobile Security (Enterprise) 9.8 SP5 which could allow an authenticated remote attaEPSS 3.3%CVE-2017-11381A command injection vulnerability exists in Trend Micro Deep Discovery Director 1.1 that allows an attacker to restore accounts that can accEPSS 3.1%CVE-2023-32528Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains vulnerable .php files that could allow a remote attacker to execute arbitrary codeEPSS 3.0%CVE-2023-32527Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains vulnerable .php files that could allow a remote attacker to execute arbitrary codeEPSS 2.9%CVE-2023-32524Affected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote user to bypass authentiEPSS 2.6%CVE-2023-32523Affected versions of Trend Micro Mobile Security (Enterprise) 9.8 SP5 contain some widgets that would allow a remote user to bypass authentiEPSS 2.6%CVE-2023-52327MEDIUMCertain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an atEPSS 2.5%