CWE-64: .LNK
The product, when opening a file or directory, does not sufficiently handle when the file is a Windows shortcut (.LNK) whose target is outside of the intended control sphere. This could allow an attacker to cause the product to operate on unauthorized files.
9 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2025-53503 — Trend Micro Cleaner One Pro is vulnerable to a Privilege Escalation vulnerability that could allow a local attacker to u
- CVE-2025-52837 — Trend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link Following Privilege Escalat
- CVE-2025-52521 — Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that cou
- CVE-2025-49385 — Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that cou
- CVE-2025-49384 — Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that cou
- CVE-2025-48443 — Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Local Privilege E
- CVE-2025-7376 — Information Tampering Vulnerability in Multiple Processes of GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, AnalytiX, IoTWorX, MC Works64, and GENESIS
Recently published
- CVE-2025-7376 — Information Tampering Vulnerability in Multiple Processes of GENESIS64, ICONICS Suite, MobileHMI, Hyper Historian, AnalytiX, IoTWorX, MC Works64, and GENESIS
- CVE-2025-53503 — Trend Micro Cleaner One Pro is vulnerable to a Privilege Escalation vulnerability that could allow a local attacker to u
- CVE-2025-52837 — Trend Micro Password Manager (Consumer) version 5.8.0.1327 and below is vulnerable to a Link Following Privilege Escalat
- CVE-2025-52521 — Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that cou
- CVE-2025-49385 — Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that cou
- CVE-2025-49384 — Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that cou
- CVE-2025-48443 — Trend Micro Password Manager (Consumer) version 5.0.0.1266 and below is vulnerable to a Link Following Local Privilege E