The vulnerabilities lie in the way Trend Micro Apex Central handles certain input, according to the NCSC. An attacker could cause a denial-of-service (DoS) without authentication by exploiting an unchecked NULL return value. Additionally, attackers could gain unauthenticated access to load malicious DLLs into a critical executable, potentially leading to arbitrary code execution with SYSTEM privileges. This could compromise the integrity and security of the affected systems.
There are three different vulnerabilities involved, Trend Micro reports :
- CVE-2025-69258: LoadLibraryEX Remote Code Execution (RCE)
- CVE-2025-69259: Message Unchecked NULL Return Value Denial of Service (DoS)
- CVE-2025-69260: Message Out-of-bounds Read Denial of Service (DoS)
The severity of CVE-2025-69258 has been rated at 9.8 out of 10 by the CVSS. CVE-2025-69259 and CVE-2025-69260 have both been rated at 7.5.