트렌드 마이크로 Apex One 취약점, 서버 위험 초래
8월 18, 2025 • César Daniel Barreto

Image credit: Photo by Rebecca Wang / CC BY 4.0
보안 팀은 주목해야 합니다 시사 CVE-2025-54948을 그들의 알려진 취약점 목록에 추가했습니다, and hackers already love this one. Now we’re dealing with a CVSS of like 9.4 in Trend Micro’s Apex One – this bug lets 공격자들이 인증 없이 OS 명령을 실행할 수 있습니다. 누군가가 당신의 관리 콘솔에 포트 8080 또는 4343에서 접근한다면, 그들은 기본적으로 IUSR로 서버를 실행할 수 있습니다.
The technical side, well, it’s pretty ugly: 백엔드 입력 검증이 부족하여 이러한 악성 페이로드가 시스템 수준 실행 을 할 수 있게 합니다. 그리고 네, 이 문제는 온프레미스 관리 콘솔 버전 20216까지 포함됩니다 서버 버전 14039 and lower. There’s another bug, CVE-2025-54987, targeting different CPU 설정 –- 공격자들에게 여러 공격 경로를 제공합니다.
When it comes to fixing, Trend Micro doesn’t have a real solution yet, just some stop-gap tool that mucks up Remote Install Agent functions. The tool does work, but installing stuff might be a chore with UNC paths until a true patch arrives. By the way, if you’re on cloud versions of Apex One, as of July 31, you’re mostly safe, but those on-prem folks, well, they’re tied to this temporary fix for now.
Warning: got Apex One management consoles lying around exposed? Get that fix tool going pronto and switch off network access to those management IPs. It’s worth mentioning that federal agencies have their BOD 22-01 changes to worry about, but really, every organization should see this as a top priority. Since CISA has placed it into KEV, exploit attempts are nonstop and spreading fast.

세자르 다니엘 바레토
세자르 다니엘 바레토는 존경받는 사이버 보안 작가이자 전문가로, 복잡한 사이버 보안에 대한 심도 있는 지식과 복잡한 사이버 보안 주제를 단순화하는 능력으로 유명합니다. 네트워크 보안 및 데이터 보호에 대한 폭넓은 경험을 바탕으로 보안 및 데이터 보호 분야에서 폭넓은 경험을 쌓은 그는 정기적으로 최신 사이버 보안 트렌드에 대한 사이버 보안 트렌드에 대한 통찰력 있는 기사와 분석을 정기적으로 제공하고 있습니다.