CVE-2025-53378
Trend Micro Worry-Free Business Security Service vulnerability analysis and mitigation

A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticated attacker to remotely take control of the agent on affected installations.

Also note: this vulnerability only affected the SaaS client version of WFBSS only, meaning the on-premise version of Worry-Free Business Security was not affected, and this issue was addressed in a WFBSS monthly maintenance update. Therefore no other customer action is required to mitigate if the WFBSS agents are on the regular SaaS maintenance deployment schedule and this disclosure is for informational purposes only.


SourceNVD

Related Trend Micro Worry-Free Business Security Service vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-53378CRITICAL9.8
  • Trend Micro Worry-Free Business Security ServiceTrend Micro Worry-Free Business Security Service
  • cpe:2.3:a:trendmicro:worry-free_business_security_services
NoYesJul 10, 2025
CVE-2025-49154HIGH7.8
  • Trend Micro Apex One AgentTrend Micro Apex One Agent
  • cpe:2.3:a:trendmicro:worry-free_business_security_services
NoYesJun 17, 2025
CVE-2022-24680HIGH7.8
  • Trend Micro Apex One AgentTrend Micro Apex One Agent
  • cpe:2.3:a:trendmicro:apex_one
NoNoFeb 24, 2022
CVE-2022-24679HIGH7.8
  • Trend Micro Apex One AgentTrend Micro Apex One Agent
  • cpe:2.3:a:trendmicro:apex_one
NoNoFeb 24, 2022
CVE-2025-49487MEDIUM6.8
  • Trend Micro Worry-Free Business Security ServiceTrend Micro Worry-Free Business Security Service
  • cpe:2.3:a:trendmicro:worry-free_business_security_services
NoYesJun 17, 2025

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management