Direct naar de inhoud
Kritieke cyberalerts voor jouw sector & systemen — direct in je inbox. Aanmelden →
cybernieuws.nl Cybersecurity en informatiebeveiling nieuws alerts live · 12 min 99 bronnen 3 kritiek 2 vandaag
CVE's Videos

← Terug naar CVE-database

CVE-2025-71215

HIGH · 7.0 CVSS Gepubliceerd: CWE-367

Beschrijving NL

Een time-of-check time-of-use kwetsbaarheid in de Trend Micro Apex One (mac) agent iCore service handtekeningverificatie kan een lokale aanvaller in staat stellen om privileges op getroffen installaties te escaleren. Let op: een aanvaller moet eerst de mogelijkheid krijgen om low-privileged code op het doelsysteem uit te voeren om deze kwetsbaarheid te exploiteren. De volgende informatie wordt alleen ter informatie verstrekt voor CVE-referenties, omdat deze al zijn geadresseerd via ActiveUpdate/SaaS-updates medio tot eind 2025 (SaaS 2507 & 2005 Annual Release).

Origineel (Engels) tonen

A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent iCore service signature verification could allow a local attacker to escalate privileges on affected installations.

Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The following information is provided as informational only for CVE references, as these were addressed already via ActiveUpdate/SaaS updates in mid to late 2025 (SaaS 2507 & 2005 Yearly Release).

Vendors

Trendmicro

Affected products

Apex One

References