U.S. flag   An official website of the United States government
Dot gov

Official websites use .gov
A .gov website belongs to an official government organization in the United States.

Https

Secure .gov websites use HTTPS
A lock (Dot gov) or https:// means you've safely connected to the .gov website. Share sensitive information only on official, secure websites.

Vulnerability Change Records for CVE-2025-49487

Change History

New CVE Received from Trend Micro, Inc. 6/17/2025 3:15:34 PM

Action Type Old Value New Value
Added Tag

								
							
							
						
exclusively-hosted-service
Added Description

								
							
							
						
An uncontrolled search path vulnerability in the Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an attacker with physical access to a machine to execute arbitrary code on affected installations.

An attacker must have had physical access to the target system in order to exploit this vulnerability due to need to access a certain hardware component.

Also note: this vulnerability only affected the SaaS client version of WFBSS only, meaning the on-premise version of Worry-Free Business Security was not affected, and this issue was addressed in a previous WFBSS monthly maintenance update. Therefore no other customer action is required to mitigate if the WFBSS agents are on the regular SaaS maintenance deployment schedule and this disclosure is for informational purposes only.
Added CVSS V3.1

								
							
							
						
AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Added CWE

								
							
							
						
CWE-427
Added Reference

								
							
							
						
https://success.trendmicro.com/en-US/solution/KA-0019936
Added Reference

								
							
							
						
https://www.zerodayinitiative.com/advisories/ZDI-25-360/