CVE-2025-49385
Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.8
- CVSS vector
- CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
- EPSS probability
- 0.17%
- CWE
- CWE-64
- Published
- 2025-06-17
- Last modified
- 2026-03-13
Affected products
- Trend Micro, Inc. Trend Micro Internet Security (Consumer)
Weakness type
Related vulnerabilities
- CVE-2025-7376 — Information Tampering Vulnerability in Multiple Processes of GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, AnalytiX, IoTWorX, MC Works64, and GENESIS
- CVE-2025-53503 — Trend Micro Cleaner One Pro is vulnerable to a Privilege Escalation vulnerability that could allow...
- CVE-2025-52837 — Trend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link...
- CVE-2025-52521 — Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation...
- CVE-2025-49384 — Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation...
- CVE-2025-48443 — Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link...
- CVE-2021-41562 — Deletion of arbitrary files vulnerability in Snow Agent for Windows
- CVE-2021-1492 — Duo Authentication Proxy Installer Denial of Service Vulnerability