ZDI-26-148: Trend Micro Apex Central Improper Authentication Privilege Escalation Vulnerability
This vulnerability allows remote attackers to escalate privileges on affected installations of Trend Micro Apex Central. Authentication is required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.1. The following CVEs are assigned: CVE-2025-71209.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-148?
The vulnerability ZDI-26-148 is rated with a CVSS score that reflects its potential to lead to privilege escalation.
How do I fix ZDI-26-148?
To mitigate ZDI-26-148, ensure you apply the latest security updates and patches provided by Trend Micro for Apex Central.
What type of attacks can ZDI-26-148 facilitate?
ZDI-26-148 can facilitate privilege escalation attacks by allowing authenticated users to gain unauthorized access to higher-level privileges.
Is authentication required to exploit ZDI-26-148?
Yes, authentication is required for an attacker to exploit the ZDI-26-148 vulnerability.
Which software is affected by ZDI-26-148?
ZDI-26-148 specifically affects Trend Micro Apex Central installations.