« Volver al listado

CVE-2025-71210

Estado: AnalizadaCrítica (9.8)—

A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations.

Please note: although this vulnerability carries a technical critical CVSS rating, this was reported via responsible disclosure via a researcher through the Zero Day Initiative. The SaaS versions of the product have already been mitigated and no customer action required.

For this particular vulnerability, an attacker must have access to the Trend Micro Apex One Management Console, so customers that have their console�s IP address exposed externally should consider mitigating factors such as source restrictions if not already applied.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

🎯 Técnicas ATT&CK

Cómo se explota esta vulnerabilidad y qué consigue el atacante, en el lenguaje de MITRE ATT&CK.

AV:N/PR:N permite T1190 (app expuesta). El texto menciona 'upload malicious code and execute commands', lo que implica ejecución remota de código (T1059) tras acceso a la consola. T1005 secundaria por potencial lectura de datos en el servidor comprometido.

Inferido por nuestro agente de análisis a partir de la descripción oficial, el vector CVSS y la CWE, y comprobado por un supervisor. Puede contener errores.

🛡️ Mitigaciones ATT&CK que cubren estas técnicas

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2025-71210",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2025-71210",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "yes"
            },
            {
              "technicalImpact": "total"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2026-05-21T14:10:09.359975Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "security@trendmicro.com",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 9.8,
          "attackVector": "NETWORK",
          "baseSeverity": "CRITICAL",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H",
          "integrityImpact": "HIGH",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "HIGH",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 5.9,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "security@trendmicro.com",
      "affectedData": [
        {
          "cpes": [
            "cpe:2.3:a:trendmicro:apexone_op:14.0.0.14136:*:*:*:*:*:*:*"
          ],
          "vendor": "Trend Micro, Inc.",
          "product": "TrendAI Apex One",
          "versions": [
            {
              "status": "affected",
              "version": "2019 (14.0)",
              "lessThan": "14.0.0.14136",
              "versionType": "semver"
            }
          ]
        },
        {
          "cpes": [
            "cpe:2.3:a:trendmicro:apexone_saas:14.0.0.20315:*:*:*:*:*:*:*"
          ],
          "vendor": "Trend Micro, Inc.",
          "product": "TrendAI Apex One as a Service",
          "versions": [
            {
              "status": "affected",
              "version": "SaaS",
              "lessThan": "14.0.20315",
              "versionType": "semver"
            }
          ]
        }
      ]
    }
  ],
  "published": "2026-05-21T14:16:43.540",
  "references": [
    {
      "url": "https://success.trendmicro.com/en-US/solution/KA-0022458",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "security@trendmicro.com"
    },
    {
      "url": "https://www.zerodayinitiative.com/advisories/ZDI-26-136/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "security@trendmicro.com"
    }
  ],
  "vulnStatus": "Analyzed",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "security@trendmicro.com",
      "description": [
        {
          "lang": "en",
          "value": "CWE-22"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "A vulnerability in the Trend Micro Apex One management console could allow a remote attacker to upload malicious code and execute commands on affected installations.\r\n\r\nPlease note: although this vulnerability carries a technical critical CVSS rating, this was reported via responsible disclosure via a researcher through the Zero Day Initiative. The SaaS versions of the product have already been mitigated and no customer action required.\r\n\r\nFor this particular vulnerability, an attacker must have access to the Trend Micro Apex One Management Console, so customers that have their console�s IP address exposed externally should consider mitigating factors such as source restrictions if not already applied."
    },
    {
      "lang": "es",
      "value": "Una vulnerabilidad en la consola de gestión de Trend Micro Apex One podría permitir a un atacante remoto cargar código malicioso y ejecutar comandos en las instalaciones afectadas.\n\nTenga en cuenta: aunque esta vulnerabilidad tiene una calificación CVSS técnica crítica, esto fue reportado a través de una divulgación responsable por un investigador a través de la Iniciativa Día Cero (Zero Day Initiative). Las versiones SaaS del producto ya han sido mitigadas y no se requiere ninguna acción por parte del cliente.\n\nPara esta vulnerabilidad en particular, un atacante debe tener acceso a la consola de gestión de Trend Micro Apex One, por lo que los clientes que tienen la dirección IP de su consola expuesta externamente deberían considerar factores de mitigación como restricciones de origen si aún no se han aplicado."
    }
  ],
  "lastModified": "2026-07-23T16:10:00.137",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:trendmicro:apex_one:*:*:*:*:on-premises:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "739767A5-60D4-47F4-8C64-4D467B577EA1",
              "versionEndExcluding": "14.0.0.14136"
            },
            {
              "criteria": "cpe:2.3:a:trendmicro:apex_one:*:*:*:*:saas:windows:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E2FF211F-6A51-4E98-83A1-AC18122E2473",
              "versionEndExcluding": "14.0.20315"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "security@trendmicro.com"
}