B
今週中
トレンドマイクロの「TrendAI Vision One」において、深刻な脆弱性2件
📌 一言でいうと
トレンドマイクロの「TrendAI Vision One」において、深刻な脆弱性2件が公開されました。CVE-2025-71386はリモートからの情報漏洩(CVSS 9.9)、CVE-2025-71387は権限昇格(CVSS 7.2)を可能にするものです。これらの脆弱性は2025年後半にバックエンドで修正済みであり、Service Gatewayアプライアンスについてはファームウェア3.0.24および3.0.25で対処されています。
ℹ️ これは他社で発生した事案の情報です。貴社が当該サービスを利用していない場合は、参考情報としてご確認ください。同様の攻撃手法に対する備えのきっかけとしてもご活用いただけます。
🔍該当判定
- トレンドマイクロ社の「TrendAI Vision One」を導入して利用している
- 「TrendAI Vision One」の「Service Gateway」アプライアンスを社内で運用している
- 「Service Gateway」を利用しており、かつ自動アップデート機能を無効に設定している
上記いずれにも該当しない → 静観でOK
✅該当時の対応
Service Gatewayアプライアンスを利用している場合、ファームウェアが3.0.24または3.0.25以降に更新されているか確認してください。自動アップデートを無効にしている場合は、手動で更新を適用してください。
📧 メール案を見る (管理者向け)
⚠️ これは AI が生成した参考例です。配信前に必ず内容をご確認のうえ、貴社の状況に合わせて編集してご利用ください。実際の被害状況や自社の利用環境を踏まえた判断は、貴社のセキュリティ責任者にご確認ください。
件名: 【共有】TrendAI Vision One (CVE-2025-71386, CVE-2025-71387) 対応について
お疲れさまです。TrendAI Vision Oneに関する脆弱性情報共有です。
■ 概要
TrendAI Vision Oneにおいて、リモートからの情報漏洩(CVE-2025-71386 / CVSS 9.9)および権限昇格(CVE-2025-71387 / CVSS 7.2)の脆弱性が報告されました。
■ 影響範囲
- 対象製品: TrendAI Vision One
- 対象コンポーネント: Service Gateway アプライアンス
■ 対応手順
1. Service Gatewayのファームウェアバージョンを確認してください。
2. ファームウェア 3.0.24 または 3.0.25 以降が適用されているか確認し、未適用の場合は速やかに更新してください(特に自動アップデートを無効にしている環境)。
■ 参考情報
- トレンドマイクロ公式セキュリティアドバイザリ
対応優先度: 高
対応期限: 速やかに確認
お疲れさまです。TrendAI Vision Oneに関する脆弱性情報共有です。
■ 概要
TrendAI Vision Oneにおいて、リモートからの情報漏洩(CVE-2025-71386 / CVSS 9.9)および権限昇格(CVE-2025-71387 / CVSS 7.2)の脆弱性が報告されました。
■ 影響範囲
- 対象製品: TrendAI Vision One
- 対象コンポーネント: Service Gateway アプライアンス
■ 対応手順
1. Service Gatewayのファームウェアバージョンを確認してください。
2. ファームウェア 3.0.24 または 3.0.25 以降が適用されているか確認し、未適用の場合は速やかに更新してください(特に自動アップデートを無効にしている環境)。
■ 参考情報
- トレンドマイクロ公式セキュリティアドバイザリ
対応優先度: 高
対応期限: 速やかに確認
Subject: [Security Advisory] TrendAI Vision One (CVE-2025-71386, CVE-2025-71387)
Dear IT/Security Team,
We are sharing information regarding vulnerabilities identified in TrendAI Vision One.
■ Overview
Two vulnerabilities have been disclosed: CVE-2025-71386 (Remote Information Leakage, CVSS 9.9) and CVE-2025-71387 (Privilege Escalation, CVSS 7.2).
■ Scope
- Product: TrendAI Vision One
- Component: Service Gateway Appliance
■ Remediation Steps
1. Verify the current firmware version of your Service Gateway appliance.
2. Ensure that firmware version 3.0.24 or 3.0.25 (or later) is applied. Manual updates are required if automatic updates are disabled.
■ Reference
- Trend Micro Official Security Advisory
Priority: High
Deadline: Immediate verification
Dear IT/Security Team,
We are sharing information regarding vulnerabilities identified in TrendAI Vision One.
■ Overview
Two vulnerabilities have been disclosed: CVE-2025-71386 (Remote Information Leakage, CVSS 9.9) and CVE-2025-71387 (Privilege Escalation, CVSS 7.2).
■ Scope
- Product: TrendAI Vision One
- Component: Service Gateway Appliance
■ Remediation Steps
1. Verify the current firmware version of your Service Gateway appliance.
2. Ensure that firmware version 3.0.24 or 3.0.25 (or later) is applied. Manual updates are required if automatic updates are disabled.
■ Reference
- Trend Micro Official Security Advisory
Priority: High
Deadline: Immediate verification