Views:

Release Date: June 09, 2025

CVE Vulnerability Identifier: CVE-2025-49384

Platform: Microsoft Windows

CVSSv3 Scores: 7.8: AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Severity Rating: High

Summary

Trend Micro has released an update via ActiveUpdate for the Trend Micro Security for Windows family of consumer products which resolves a link following privilege local escalation vulnerability by updating the libraries in version 17.8 or higher of the software.

Affected Version(s)

PRODUCT AFFECTED VERSION(S) PLATFORM LANGUAGE(S)
Trend Micro Internet Security 17.8 Microsoft Windows English

Solution

PRODUCT UPDATED VERSION(S) PLATFORM LANGUAGE(S)
Trend Micro Internet Security 17.8.1464 Microsoft Windows English

Vulnerability Details

Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own.

Trend Micro has received no reports nor is aware of any actual attacks against the affected product related to this vulnerability at this time.

Acknowledgement

Trend Micro would like to thank the following individual for responsibly disclosing the issue and working with Trend Micro to help protect our customers:

  • Vladislav Berghici of Trend Research

Additional Assistance

Customers who have questions are encouraged to contact Trend Micro Support for further assistance.

External Reference

The following advisories may be found at Trend Micro's Zero Day Initiative Published Advisories site:

  • ZDI-CAN-25876
Add a comment