CVE-2025-69258

Severity CVSS v4.0:
Pending analysis
Type:
CWE-120 Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
08/01/2026
Last modified:
15/01/2026

Description

A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of attacker-supplied code under the context of SYSTEM on affected installations.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:trendmicro:apex_central:2019:-:*:*:-:*:*:*
cpe:2.3:a:trendmicro:apex_central:2019:build_3752:*:*:-:*:*:*
cpe:2.3:a:trendmicro:apex_central:2019:build_5158:*:*:-:*:*:*
cpe:2.3:a:trendmicro:apex_central:2019:build_6016:*:*:-:*:*:*
cpe:2.3:a:trendmicro:apex_central:2019:build_6288:*:*:-:*:*:*
cpe:2.3:a:trendmicro:apex_central:2019:build_6394:*:*:-:*:*:*
cpe:2.3:a:trendmicro:apex_central:2019:build_6481:*:*:-:*:*:*
cpe:2.3:a:trendmicro:apex_central:2019:build_6511:*:*:-:*:*:*
cpe:2.3:a:trendmicro:apex_central:2019:build_6571:*:*:-:*:*:*
cpe:2.3:a:trendmicro:apex_central:2019:build_6658:*:*:-:*:*:*
cpe:2.3:a:trendmicro:apex_central:2019:build_6660:*:*:-:*:*:*
cpe:2.3:a:trendmicro:apex_central:2019:build_6890:*:*:-:*:*:*
cpe:2.3:a:trendmicro:apex_central:2019:build_6955:*:*:-:*:*:*
cpe:2.3:a:trendmicro:apex_central:2019:build_7007:*:*:-:*:*:*
cpe:2.3:a:trendmicro:apex_central:2019:build_7065:*:*:-:*:*:*