ZDI: Upcoming Advisories The following is a list of vulnerabilities discovered by Zero Day Initiative researchers that are yet to be publicly disclosed. The affected vendor has been contacted on the specified date and while they work on a patch for these vulnerabilities, Trend Micro customers are protected from exploitation by IPS filters delivered ahead of public disclosure. Once the affected vendor patches the vulnerability, we publish an accompanying security advisory which describes the issue, including links to the vendor’s fixes.
- ZDI-CAN-26077: Pioneeron January 14, 2025 at 6:00 am
A CVSS score 4.6 AV:P/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:N severity vulnerability discovered by ‘Dmitry “InfoSecDJ” Janushkevich of Trend Micro Zero Day Initiative’ was reported to the affected vendor on: 2025-01-14, 8 days ago. The vendor is given until 2025-05-14 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-26079: Pioneeron January 14, 2025 at 6:00 am
A CVSS score 6.8 AV:P/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Dmitry “InfoSecDJ” Janushkevich of Trend Micro Zero Day Initiative’ was reported to the affected vendor on: 2025-01-14, 8 days ago. The vendor is given until 2025-05-14 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-25375: Trend Microon January 14, 2025 at 6:00 am
A CVSS score 7.8 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Anonymous’ was reported to the affected vendor on: 2025-01-14, 8 days ago. The vendor is given until 2025-05-14 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-26078: Pioneeron January 14, 2025 at 6:00 am
A CVSS score 4.4 AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:H/A:N severity vulnerability discovered by ‘Dmitry “InfoSecDJ” Janushkevich of Trend Micro Zero Day Initiative’ was reported to the affected vendor on: 2025-01-14, 8 days ago. The vendor is given until 2025-05-14 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-25574: Trend Microon January 14, 2025 at 6:00 am
A CVSS score 6.7 AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Anonymous’ was reported to the affected vendor on: 2025-01-14, 8 days ago. The vendor is given until 2025-05-14 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-26153: Microsofton January 9, 2025 at 6:00 am
A CVSS score 5.3 AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:L/A:N severity vulnerability discovered by ‘Simon Zuckerbraun – Trend Micro Zero Day Initiative’ was reported to the affected vendor on: 2025-01-09, 13 days ago. The vendor is given until 2025-05-09 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-26247: Appleon January 9, 2025 at 6:00 am
A CVSS score 3.3 AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N severity vulnerability discovered by ‘Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative’ was reported to the affected vendor on: 2025-01-09, 13 days ago. The vendor is given until 2025-05-09 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-26248: Appleon January 9, 2025 at 6:00 am
A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative’ was reported to the affected vendor on: 2025-01-09, 13 days ago. The vendor is given until 2025-05-09 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-26008: IPythonon January 8, 2025 at 6:00 am
A CVSS score 7.3 AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Michael DePlante (@izobashi) of Trend Micro’s Zero Day Initiative’ was reported to the affected vendor on: 2025-01-08, 14 days ago. The vendor is given until 2025-05-08 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-26154: Appleon January 8, 2025 at 6:00 am
A CVSS score 3.3 AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N severity vulnerability discovered by ‘Hossein Lotfi (@hosselot) of Trend Micro Zero Day Initiative’ was reported to the affected vendor on: 2025-01-08, 14 days ago. The vendor is given until 2025-05-08 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-25572: Trend Microon January 8, 2025 at 6:00 am
A CVSS score 4.4 AV:L/AC:H/PR:L/UI:R/S:U/C:N/I:N/A:H severity vulnerability discovered by ‘Anonymous’ was reported to the affected vendor on: 2025-01-08, 14 days ago. The vendor is given until 2025-05-08 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-25750: JetBrainson January 8, 2025 at 6:00 am
A CVSS score 7.3 AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Anonymous’ was reported to the affected vendor on: 2025-01-08, 14 days ago. The vendor is given until 2025-05-08 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-25639: Lorexon January 8, 2025 at 6:00 am
A CVSS score 7.5 AV:A/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘phudq and namnp from Viettel Cyber Security’ was reported to the affected vendor on: 2025-01-08, 14 days ago. The vendor is given until 2025-05-08 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-25957: PDF-XChangeon January 8, 2025 at 6:00 am
A CVSS score 3.3 AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N severity vulnerability discovered by ‘Anonymous’ was reported to the affected vendor on: 2025-01-08, 14 days ago. The vendor is given until 2025-05-08 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-25941: IPythonon January 8, 2025 at 6:00 am
A CVSS score 7.3 AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Anonymous’ was reported to the affected vendor on: 2025-01-08, 14 days ago. The vendor is given until 2025-05-08 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-25831: MSYS2on January 8, 2025 at 6:00 am
A CVSS score 7.3 AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Anonymous’ was reported to the affected vendor on: 2025-01-08, 14 days ago. The vendor is given until 2025-05-08 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-25727: Rockwell Automationon January 3, 2025 at 6:00 am
A CVSS score 7.8 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘CrisprXiang With FDU and Hao Huang with FDU’ was reported to the affected vendor on: 2025-01-03, 19 days ago. The vendor is given until 2025-05-03 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-25812: Appleon December 19, 2024 at 6:00 am
A CVSS score 4.3 AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N severity vulnerability discovered by ‘Anonymous’ was reported to the affected vendor on: 2024-12-19, 34 days ago. The vendor is given until 2025-04-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-25710: Fortineton December 19, 2024 at 6:00 am
A CVSS score 7.8 AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Alexander Staalgaard’ was reported to the affected vendor on: 2024-12-19, 34 days ago. The vendor is given until 2025-04-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-25862: Ashlar-Vellumon December 19, 2024 at 6:00 am
A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Rocco Calvi (@TecR0c) with TecSecurity’ was reported to the affected vendor on: 2024-12-19, 34 days ago. The vendor is given until 2025-04-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-25779: Canonon December 19, 2024 at 6:00 am
A CVSS score 8.8 AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘YingMuo (@YingMuo) working with DEVCORE Internship Program.’ was reported to the affected vendor on: 2024-12-19, 34 days ago. The vendor is given until 2025-04-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-25756: Ashlar-Vellumon December 19, 2024 at 6:00 am
A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Rocco Calvi (@TecR0c) with TecSecurity’ was reported to the affected vendor on: 2024-12-19, 34 days ago. The vendor is given until 2025-04-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-25755: Ashlar-Vellumon December 19, 2024 at 6:00 am
A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Rocco Calvi (@TecR0c) with TecSecurity’ was reported to the affected vendor on: 2024-12-19, 34 days ago. The vendor is given until 2025-04-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-25972: Ashlar-Vellumon December 19, 2024 at 6:00 am
A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Rocco Calvi (@TecR0c) with TecSecurity’ was reported to the affected vendor on: 2024-12-19, 34 days ago. The vendor is given until 2025-04-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-25945: Ashlar-Vellumon December 19, 2024 at 6:00 am
A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Rocco Calvi (@TecR0c) with TecSecurity’ was reported to the affected vendor on: 2024-12-19, 34 days ago. The vendor is given until 2025-04-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-25681: Trend Microon December 19, 2024 at 6:00 am
A CVSS score 5.5 AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H severity vulnerability discovered by ‘NT AUTHORITY\ANONYMOUS LOGON’ was reported to the affected vendor on: 2024-12-19, 34 days ago. The vendor is given until 2025-04-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-25953: Ivantion December 19, 2024 at 6:00 am
A CVSS score 7.2 AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Kevin Salapatek’ was reported to the affected vendor on: 2024-12-19, 34 days ago. The vendor is given until 2025-04-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-25587: QNAPon December 19, 2024 at 6:00 am
A CVSS score 8.8 AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Corentin “@OnlyTheDuck” BAYET from REverse Tactics’ was reported to the affected vendor on: 2024-12-19, 34 days ago. The vendor is given until 2025-04-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-25943: Ashlar-Vellumon December 19, 2024 at 6:00 am
A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Rocco Calvi (@TecR0c) with TecSecurity’ was reported to the affected vendor on: 2024-12-19, 34 days ago. The vendor is given until 2025-04-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.
- ZDI-CAN-25944: Ashlar-Vellumon December 19, 2024 at 6:00 am
A CVSS score 7.8 AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H severity vulnerability discovered by ‘Rocco Calvi (@TecR0c) with TecSecurity’ was reported to the affected vendor on: 2024-12-19, 34 days ago. The vendor is given until 2025-04-18 to publish a fix or workaround. Once the vendor has created and tested a patch we will coordinate the release of a public advisory.