Critical Information Disclosure in Trend Micro Vision One Service Gateway (CVE‑2025‑71386) Threatens Log Data
What It Is — A vulnerability (CVE‑2025‑71386) in the Service Gateway module of Trend Micro Vision One allows an authenticated remote attacker to read log files that contain sensitive information.
Exploitability — The flaw is exploitable over the network (AV:N) with low attack complexity (AC:L). Authentication is required (PR:L). CVSS v3.1 base score 7.7 (High). Trend Micro has released a patch.
Affected Products — Trend Micro Vision One (Service Gateway component).
Why It Matters for Compliance & Audit Readiness
- SOC 2 CC6.1 (Logical Access) requires that log data be protected from unauthorized access; this issue shows a gap in that control.
- Continuous control monitoring must capture evidence that logging mechanisms are hardened and that access is logged and reviewed.
- Enterprise buyers increasingly demand proof of secure logging as part of their SOC 2 audit packages.
Recommended Actions
- Deploy Trend Micro’s security update immediately.
- Review and tighten file‑system permissions on all Vision One log directories to enforce least‑privilege access.
- Enable continuous monitoring of log‑file access and integrate the alerts into your compliance evidence repository.
Source: Zero Day Initiative Advisory