Executive brief
Trend Micro Apex One is a centralized security management platform used to protect corporate endpoints from malware and other threats. A security flaw in the software's listener service could allow a user who already has limited access to a computer to gain full administrative control (SYSTEM privileges). This could allow an attacker to bypass security controls, access sensitive data, or disable the security software entirely.
Technical details
An origin validation error (CWE-346) exists within the Apex One NT Listener service. The vulnerability stems from the service's failure to sufficiently validate the origin of commands it receives. To exploit this, an attacker must already have the ability to execute low-privileged code on the target Windows system. Successful exploitation allows the attacker to execute arbitrary code with SYSTEM privileges. Trend Micro has released Critical Patch Build 14136 for on-premises installations and Security Agent Build 14.0.20315 for SaaS versions to remediate this issue.
Affected products
- Trend Micro Apex One 2019 (On-prem) Windows; SaaS Windows
- Trend Micro Trend Vision One Endpoint - Standard Endpoint Protection SaaS Windows
Timeline
- 2025-05-02: disclosed: Vulnerability reported to vendor via ZDI
- 2026-03-03: advisory: Coordinated public release of advisory by ZDI and Trend Micro
- 2026-05-21: other: NVD publication date