CVE-2025-69258
Severity CVSS v4.0:
Pending analysis
Type:
CWE-120
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow')
Publication date:
08/01/2026
Last modified:
15/01/2026
Description
A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of attacker-supplied code under the context of SYSTEM on affected installations.
Impact
Base Score 3.x
9.80
Severity 3.x
CRITICAL
Vulnerable products and versions
| CPE | From | Up to |
|---|---|---|
| cpe:2.3:a:trendmicro:apex_central:2019:-:*:*:-:*:*:* | ||
| cpe:2.3:a:trendmicro:apex_central:2019:build_3752:*:*:-:*:*:* | ||
| cpe:2.3:a:trendmicro:apex_central:2019:build_5158:*:*:-:*:*:* | ||
| cpe:2.3:a:trendmicro:apex_central:2019:build_6016:*:*:-:*:*:* | ||
| cpe:2.3:a:trendmicro:apex_central:2019:build_6288:*:*:-:*:*:* | ||
| cpe:2.3:a:trendmicro:apex_central:2019:build_6394:*:*:-:*:*:* | ||
| cpe:2.3:a:trendmicro:apex_central:2019:build_6481:*:*:-:*:*:* | ||
| cpe:2.3:a:trendmicro:apex_central:2019:build_6511:*:*:-:*:*:* | ||
| cpe:2.3:a:trendmicro:apex_central:2019:build_6571:*:*:-:*:*:* | ||
| cpe:2.3:a:trendmicro:apex_central:2019:build_6658:*:*:-:*:*:* | ||
| cpe:2.3:a:trendmicro:apex_central:2019:build_6660:*:*:-:*:*:* | ||
| cpe:2.3:a:trendmicro:apex_central:2019:build_6890:*:*:-:*:*:* | ||
| cpe:2.3:a:trendmicro:apex_central:2019:build_6955:*:*:-:*:*:* | ||
| cpe:2.3:a:trendmicro:apex_central:2019:build_7007:*:*:-:*:*:* | ||
| cpe:2.3:a:trendmicro:apex_central:2019:build_7065:*:*:-:*:*:* |
To consult the complete list of CPE names with products and versions, see this page



