---
cve: "CVE-2025-49155"
severity: "HIGH"
cvss: 8.8
epss: "79%"
vendor: "Trend Micro, Inc."
kev: false
exploited: false
published: "2025-06-17 18:42:31"
tags: [cve, security, high]
source: tsecurity.de CVE-Dossier
exported: "2026-09-05T19:20:47+02:00"
---

# CVE-2025-49155

> 8.8 HIGH

## Beschreibung

An uncontrolled search path vulnerability in the Trend Micro Apex One Data Loss Prevention module could allow an attacker to inject malicious code leading to arbitrary code execution on affected installations.

## CVSS-Vektor

```
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
```

| Metrik | Wert | Bewertung |
|---|---|---|
| AV Angriffsvektor | Netzwerk | bad |
| AC Komplexität | Gering | bad |
| PR Privilegien | Keine | bad |
| UI Interaktion | Erforderlich | good |
| S Scope | Unverändert | good |
| C Vertraulichkeit | Hoch | bad |
| I Integrität | Hoch | bad |
| A Verfügbarkeit | Hoch | bad |

## Referenzen

- <https://success.trendmicro.com/en-US/solution/KA-0019917>
- <https://www.zerodayinitiative.com/advisories/ZDI-25-362/>

---
_Exportiert aus dem [tsecurity.de CVE-Dossier](https://tsecurity.de/cve?cve=CVE-2025-49155) · Datenquellen: EUVD (ENISA), NVD, OSV, CISA KEV, FIRST EPSS, Exploit-DB, BSI BITS_
