
Trend Micro Apex One の脆弱性 CVE-2025-71210/71211 などが FIX:RCE のおそれ https://iototsecnews.jp/2026/02/27/critical-trend-micro-apex-one-vulnerabilities-allow-remote-malicious-code-execution/ Trend Micro の Apex One において、合計で 8 件の脆弱性 CVE-2025-71210~CVE-2025-71217 が修正されました。最も深刻なのは、管理コンソールのディレクトリ・トラバーサルの脆弱性CVE-2025-71210/71211 であり、未認証のリモート攻撃者によるサーバ上での任意のコード実行 (RCE) が可能になります。その他にも、Windows/macOS のエージェントにおけるローカル権限昇格 (LPE) の脆弱性も修正されています。オンプレミス版 (Apex One 2019) を利用している組織は、直ちに Critical Patch Build 14136 を適用する必要があると、同社は指摘しています。SaaS 版の利用者は、エージェントが Build 14.0.20315 以降であることを確認する必要があります。 #ApexOne #CVE202571210 #CVE202571211 #CVE202571212 #CVE202571213 #CVE202571214 #CVE202571215 #CVE202571216 #CVE202571217 #TrendMicro #Vulnerability
Post summary
The article reports that Trend Micro has fixed eight CVEs in Apex One, including RCE and LPE flaws, and urges users to apply the specified Critical Patch Builds to mitigate the risk.
