CVE-2025-71215
Beschrijving NL
Een time-of-check time-of-use kwetsbaarheid in de Trend Micro Apex One (mac) agent iCore service handtekeningverificatie kan een lokale aanvaller in staat stellen om privileges op getroffen installaties te escaleren. Let op: een aanvaller moet eerst de mogelijkheid krijgen om low-privileged code op het doelsysteem uit te voeren om deze kwetsbaarheid te exploiteren. De volgende informatie wordt alleen ter informatie verstrekt voor CVE-referenties, omdat deze al zijn geadresseerd via ActiveUpdate/SaaS-updates medio tot eind 2025 (SaaS 2507 & 2005 Annual Release).
Origineel (Engels) tonen
A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent iCore service signature verification could allow a local attacker to escalate privileges on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The following information is provided as informational only for CVE references, as these were addressed already via ActiveUpdate/SaaS updates in mid to late 2025 (SaaS 2507 & 2005 Yearly Release).