Trend Micro has released security updates to address vulnerabilities affecting on-premise versions of Apex Central for Windows, including a critical flaw that could lead to arbitrary code execution.

The vulnerability, tracked as CVE-2025-69258, has a CVSS score of 9.8/10.0. It is described as a “remote code execution” vulnerability affecting LoadLibraryEX. A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load a malicious DLL into a core executable. This, in turn, could lead to code execution under the SYSTEM context.
See also: Critical vulnerability in jsPDF allows arbitrary file reading on Node.js installations
Trend Micro fixes two more vulnerabilities in Apex Central
A second vulnerability patched by Trend Micro is CVE-2025-69259 (CVSS score: 7.5). It concerns an unchecked NULL return value that could allow a remote, unauthenticated attacker to create a denial-of-service condition on affected installations.

Finally, the vulnerability CVE-2025-69260 (CVSS score: 7.5) is a message out-of-bounds read, which could also allow a remote, unauthenticated attacker to create a denial-of-service condition on affected installations.
See also: Coolify: 11 critical security vulnerabilities allow complete server compromise
Tenable discovered and reported the three vulnerabilities in August 2025, explaining that an attacker can exploit CVE-2025-69258 by sending a “ 0x0a8d ” (“SC_INSTALL_HANDLER_REQUEST”) message to the MsgReceiver.exe component and causing a malicious DLL into the binary. This could allow code execution to be loaded with elevated privileges.
Similarly, CVE-2025-69259 and CVE-2025-69260 can be triggered by sending a specially crafted “0x1b5b” (“SC_CMD_CGI_LOG_REQUEST”) message to the MsgReceiver.exe.

The issues affect on-premise versions of Apex Central below Build 7190.Trend Micro noted that successful exploitation depends on whether an attacker already has physical or remote access to a vulnerable point.
See also: Vulnerability in Linux battery tool allows changing system settings
“In addition to timely implementation of updates and fixes, customers are also urged to review remote access to critical systems and ensure policies and perimeter security are up to date,” he added.
