Trend Micro Confirms Active Exploitation of Critical Apex One Flaws in On
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-54948 | Pre-auth OS command injection in Trend Micro Apex One on-prem Management Console Trend Micro Apex One's on-premises Management Console contains an OS command injection flaw (CWE-78) that a remote attacker can reach prior to authentication. By sending crafted requests to the console, the attacker can inject arbitrary OS commands and upload malicious code to the server hosting the console. Successful exploitation yields remote code execution on the Apex One management server, which typically holds privileged network access and controls the managed endpoint fleet. Only organizations running the on-premise Apex One Management Console are affected; the source data does not enumerate specific vulnerable builds. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-08-18, confirming active exploitation in the wild, though no public proof-of-concept is known and ransomware involvement is not yet confirmed. Do: Apply Trend Micro's patched builds or vendor-directed mitigations for the on-prem Apex One Management Console immediately, per the CISA KEV required action and BOD 22-01 guidance (federal agencies face a KEV deadline). Restrict the Management Console from direct internet exposure via firewall or VPN, and hunt the management server for signs of compromise such as unexpected uploaded files or processes, since active exploitation is confirmed. Ransomware association is unconfirmed but should be assumed possible until vendor guidance says otherwise. | 9.8 | 22% | KEV |
| large≈ tens of thousands of on-prem Management Console deployments (estimate; no published install counts in source data) | |
| CVE-2025-54987 | A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute com A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations. This vulnerability is essentially the same as CVE-2025-54948 but targets a different CPU architecture. NVD description · AI analysis pending | 9.8 | 17% |
| — |
Full article439 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananAug 06, 2025Vulnerability / Endpoint Security
Trend Micro has released mitigations to address critical security flaws in on-premise versions of Apex One Management Console that it said have been exploited in the wild.
The vulnerabilities (CVE-2025-54948 and CVE-2025-54987), both rated 9.4 on the CVSS scoring system, have been described as management console command injection and remote code execution flaws.
"A vulnerability in Trend Micro Apex One (on-premise) management console could allow a pre-authenticated remote attacker to upload malicious code and execute commands on affected installations," the cybersecurity company said in a Tuesday advisory.
While both shortcomings are essentially the same, CVE-2025-54987 targets a different CPU architecture. The Trend Micro Incident Response (IR) Team and Jacky Hsieh at CoreCloud Tech have been credited with reporting the two flaws.
According to ZeroPath, CVE-2025-54948 stems from a lack of sufficient input validation in the management console's backend, thereby allowing a remote attacker with access to the management console interface to craft payloads that inject malicious operating system commands and result in remote code execution.
There are currently no details on how the issues are being exploited in real-world attacks. Trend Micro said it "observed at least one instance of an attempt to actively exploit one of these vulnerabilities in the wild."
Mitigations for Trend Micro Apex One as a Service and Trend Vision One Endpoint Security - Standard Endpoint Protection have already been deployed as of July 31, 2025. A short-term solution for on-premise versions is available in the form of a fix tool. A formal patch for the vulnerabilities is expected to be released in mid-August 2025.
However, Trend Micro pointed out that while the tool fully protects against known exploits, it will disable the ability for administrators to utilize the Remote Install Agent function to deploy agents from the Trend Micro Apex One Management Console. It emphasized that other agent install methods, such as UNC path or agent package, are unaffected.
"Exploiting these type of vulnerabilities generally require that an attacker has access (physical or remote) to a vulnerable machine," the company said. "In addition to timely application of patches and updated solutions, customers are also advised to review remote access to critical systems and ensure policies and perimeter security is up-to-date."
Another prerequisite for successful exploitation is that the attacker must have access to the Trend Micro Apex One Management Console. Therefore, customers that have their console's IP address exposed externally are recommended to implement source restrictions if not already applied.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/08/trend-micro-confirms-active.html