Source: Ministry of education information & communication security contingency platform
"" "" ""
| Publication Number | TACERT-ANA-2026011210015858 | Publication Time | 2026/01/12 10:52 |
| Incident Type | ANA-Vulnerability Alert | Discovery Time | 2026/01/12 10:52 |
| Impact Level | Low | ||
| [Subject] 【Vulnerability Alert】A Critical Security Vulnerability Has Been Identified in Trend Micro Apex Central (CVE-2025-69258) |
|||
| [Content] Forwarded from TWCERTCC-200-202601-00000005 Trend Micro Apex Central is a centralized management platform developed by Trend Micro, used to manage multiple Trend Micro security solutions, including gateways, mail servers, file servers, and enterprise desktops. Recently, a critical security advisory was released for this vulnerability (CVE-2025-69258, CVSS: 9.8). The vulnerability stems from a security weakness in the LoadLibraryEX function used by Trend Micro Apex Central. An attacker can remotely load a malicious DLL under their control into critical executables on the system without authentication, and execute attacker-controlled code with SYSTEM privileges. (Information Sharing Level: WHITE (Information content can be publicly disclosed) |
|||
| [Affected Platform] Apex Central (on-premise) versions earlier than 7190 (exclusive) |
|||
|
[Recommended Actions] https://success.trendmicro.com/en-US/solution/KA-0022071 |
|||
| [Reference] https://www.twcert.org.tw/tw/cp-169-10619-c1e07-1.html |
|||