CVE-2025-47867: Trend Micro Apex Central widget getBlock Local File Inclusion Remote Code Execution Vulnerability
A Local File Inclusion vulnerability in a Trend Micro Apex Central widget in versions below 8.0.6955 could allow an attacker to include arbitrary files to execute as PHP code and lead to remote code execution on affected installations.
Other sources
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Trend Micro Apex Central. Authentication is required to exploit this vulnerability. The specific flaw exists within the getBlock function. The issue results from the lack of proper validation of user-supplied data prior to passing it to a PHP include function. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of IUSR.
— ZDI
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-47867?
CVE-2025-47867 is classified as a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2025-47867?
To fix CVE-2025-47867, upgrade to Trend Micro Apex Central version 8.0.6955 or later.
What software is affected by CVE-2025-47867?
CVE-2025-47867 affects Trend Micro Apex Central versions below 8.0.6955.
What type of vulnerability is CVE-2025-47867?
CVE-2025-47867 is a Local File Inclusion (LFI) vulnerability.
Can CVE-2025-47867 lead to remote code execution?
Yes, CVE-2025-47867 can allow attackers to execute arbitrary PHP code remotely.