Trend Micro released fixes for three vulnerabilities in Apex Central for Windows, including a critical unauthenticated remote code execution flaw in MsgReceiver.exe, the service that listens on TCP port 20001. Tracked as CVE-2025-69258, the bug lets an attacker send a crafted message that causes the service to load an attacker-controlled DLL via LoadLibraryExA, including from a UNC path, potentially yielding SYSTEM-level code execution. Public reporting indicates the vulnerable logic resides in msgHandlerLogReceiver.dll, and a proof of concept for the critical issue is available.
Two additional high-severity flaws, CVE-2025-69259 and CVE-2025-69260, can be exploited remotely without authentication to crash MsgReceiver.exe and cause denial of service through malformed messages tied to message ID 0x1b5b. One issue stems from missing validation after strstr() can return NULL, while the other involves advancing an internal buffer cursor beyond the end of the buffer, leading to an out-of-bounds read and service failure. The vulnerabilities affect Apex Central versions earlier than Build 7190, and defenders are urged to upgrade immediately or restrict access to trusted IP addresses if patching cannot be completed at once.

Mallory correlates global threat intelligence with your attack surface — know if you’re exposed before adversaries strike.
2 events from the most recent confirmed update back to the earliest known activity.
Tenable disclosed technical details for the three Apex Central vulnerabilities, including how CVE-2025-69258 can force MsgReceiver.exe to load an attacker-controlled DLL and how the two other flaws can crash the service. The advisory included proof-of-concept Python scripts and analysis of vulnerable logic in msgHandlerLogReceiver.dll.
Trend Micro issued security updates for Apex Central for Windows to remediate three vulnerabilities in MsgReceiver.exe, including critical RCE CVE-2025-69258 and DoS flaws CVE-2025-69259 and CVE-2025-69260. The fixes apply to affected versions earlier than Build 7190, with users advised to upgrade to at least Build 7190.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
3 references tracked. Mallory keeps watching after this page renders.
csirt.sk
Open sourcetenable.com
Open sourcesuccess.trendmicro.com
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.