Generated remediation guidance and an executive summary. No account required.
An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allow a local attacker to overwrite key memory-mapped files which could then have severe consequences for the security and stability of affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Use CWE-284, Trendmicro vendor hub and Worry-Free Business Security product page to widen CVE-2025-49154 into its surrounding weakness, vendor, and product context.
Compare it with CVE-2023-41179, CVE-2022-36336 and CVE-2022-24680 for nearby disclosures in the same product family. Additional editorial context is available in Cybersecurity Weekly Roundup: April 27, 2026 — Critical Zero-Days and Framework Failures.