A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticated attacker to remotely take control of the agent on affected installations. Also note: this vulnerability only affected the SaaS client version of WFBSS only, meaning the on-premise version of Worry-Free Business Security was not affected, and this issue was addressed in a WFBSS monthly maintenance update. Therefore no other customer action is required to mitigate if the WFBSS agents are on the regular SaaS maintenance deployment schedule and this disclosure is for informational purposes only.
History

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00067}

epss

{'score': 0.00072}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00067}


Thu, 10 Jul 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Jul 2025 19:00:00 +0000

Type Values Removed Values Added
Description A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticated attacker to remotely take control of the agent on affected installations. Also note: this vulnerability only affected the SaaS client version of WFBSS only, meaning the on-premise version of Worry-Free Business Security was not affected, and this issue was addressed in a WFBSS monthly maintenance update. Therefore no other customer action is required to mitigate if the WFBSS agents are on the regular SaaS maintenance deployment schedule and this disclosure is for informational purposes only.
First Time appeared Trendmicro
Trendmicro wfbs Saas
Weaknesses CWE-306
CPEs cpe:2.3:a:trendmicro:wfbs_saas:20240325:ga:*:*:*:*:*:*
Vendors & Products Trendmicro
Trendmicro wfbs Saas
References
Metrics cvssV3_1

{'score': 7.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: trendmicro

Published: 2025-07-10T18:58:55.645Z

Updated: 2025-07-10T19:06:00.457Z

Reserved: 2025-06-27T14:39:20.760Z

Link: CVE-2025-53378

cve-icon Vulnrichment

Updated: 2025-07-10T19:05:57.924Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-07-10T19:15:26.177

Modified: 2025-07-15T13:14:49.980

Link: CVE-2025-53378

cve-icon Redhat

No data.