CVE-2025-53378
Unknown Unknown - Not Provided
BaseFortify

Publication date: 2025-07-10

Last updated on: 2025-10-03

Assigner: Trend Micro, Inc.

Description
A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticated attacker to remotely take control of the agent on affected installations. Also note: this vulnerability only affected the SaaS client version of WFBSS only, meaning the on-premise version of Worry-Free Business Security was not affected, and this issue was addressed in a WFBSS monthly maintenance update. Therefore no other customer action is required to mitigate if the WFBSS agents are on the regular SaaS maintenance deployment schedule and this disclosure is for informational purposes only.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2025-07-10
Last Modified
2025-10-03
Generated
2026-05-07
AI Q&A
2025-07-10
EPSS Evaluated
2026-05-05
NVD
EUVD
Affected Vendors & Products
Showing 3 associated CPEs
Vendor Product Version / Range
trendmicro worry-free_business_security_services From 6.7.0.0 (inc) to 6.7.3954 (exc)
trendmicro worry-free_business_security_services From 14.0.0 (inc) to 14.3.1299 (exc)
microsoft windows *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-306 The product does not perform any authentication for functionality that requires a provable user identity or consumes a significant amount of resources.
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability impact me? :

An attacker exploiting this vulnerability could remotely take control of the WFBSS agent without authentication, potentially leading to unauthorized access and control over the security agent on your system. This could compromise the security of the affected system.


Can you explain this vulnerability to me?

This vulnerability is a missing authentication flaw in the Trend Micro Worry-Free Business Security Services (WFBSS) SaaS client agent. It could allow an unauthenticated attacker to remotely take control of the agent on affected installations.


What immediate steps should I take to mitigate this vulnerability?

Ensure that your Trend Micro Worry-Free Business Security Services (WFBSS) agents are on the regular SaaS maintenance deployment schedule and have applied the monthly maintenance update that addresses this vulnerability. No other customer action is required if the agents are up to date.


Ask Our AI Assistant
Need more information? Ask your question to get an AI reply (Powered by our expertise)
0/70
EPSS Chart