CVE 7 HIGH

CVE-2025-71215_CVE-2025-71215

7 / 10
HIGH
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H

Description

A time-of-check time-of-use vulnerability in the Trend Micro Apex One (mac) agent iCore service signature verification could allow a local attacker to escalate privileges on affected installations.

Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The following information is provided as informational only for CVE references, as these were addressed already via ActiveUpdate/SaaS updates in mid to late 2025 (SaaS 2507 & 2005 Yearly Release).

Basic Information

ID CVE-2025-71215
Source trendmicro
Published May 21, 2026 at 13:02
Modified May 21, 2026 at 14:02

Affected Product

Vendor Trend Micro, Inc.
Product TrendAI Apex One (Mac)
Version NA
Affected Versions Trend Micro, Inc. TrendAI Apex One (Mac) NA

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.