Executive brief
Trend Micro Apex One is a security platform used to protect corporate endpoints from malware and cyber threats. A vulnerability in its scanning engine could allow a user who already has limited access to a computer to gain full administrative control (SYSTEM privileges). This could lead to the complete takeover of the affected machine, allowing an attacker to bypass security controls or delete critical system files.
Technical details
A link following vulnerability (CWE-59) exists within the Virus Scan Engine of Trend Micro Apex One. The flaw resides in how the VSApiNt.sys driver handles file operations, which can be manipulated via symbolic links. A local attacker with low-privileged code execution can exploit this to delete arbitrary files or gain SYSTEM-level privileges. The vulnerability affects both on-premises Apex One 2019 and SaaS-based Vision One Endpoint agents on Windows. Trend Micro has released Critical Patch Build 14136 for on-premises and Security Agent Build 14.0.20315 for SaaS versions to remediate the issue.
Affected products
- Trend Micro Apex One 2019 (On-prem) Windows; SaaS Windows
- Trend Micro Trend Vision One Endpoint - Standard Endpoint Protection SaaS Windows
Timeline
- 2024-08-14: other: Vulnerability reported to vendor
- 2026-03-03: advisory: Coordinated public release by ZDI
- 2026-05-21: disclosed: NVD publication date