ZDI-26-149: Trend Micro Cleaner One Pro Link Following Denial-of-Service Vulnerability
This vulnerability allows local attackers to create a denial-of-service condition on affected installations of Trend Micro Cleaner One Pro. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 5.0. The following CVEs are assigned: CVE-2025-71218.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-149?
The severity of ZDI-26-149 is classified as a denial-of-service vulnerability.
How do I fix ZDI-26-149?
To fix ZDI-26-149, ensure your installation of Trend Micro Cleaner One Pro is updated to the latest version provided by the vendor.
Who is affected by ZDI-26-149?
ZDI-26-149 affects users of Trend Micro Cleaner One Pro on systems where local attackers can execute low-privileged code.
What type of vulnerability is ZDI-26-149?
ZDI-26-149 is a denial-of-service vulnerability that can disrupt the normal operation of Trend Micro Cleaner One Pro.
Can ZDI-26-149 be exploited remotely?
No, ZDI-26-149 requires local access to execute low-privileged code for the denial-of-service attack.