Junglewise Threat Intelligence

CVE-2025-71217: Trend Micro Apex One (mac) privilege escalation in TmSelfProtect

CVE-2025-71217 · Severity: info · CVSS 7.8 · Published 2026-05-21

Vendors: Trend Micro.

Executive brief

A security vulnerability exists in the Trend Micro Apex One agent for macOS, which is used to protect corporate endpoints from malware and threats. A local user with limited access could exploit a flaw in the software's self-protection mechanism to gain full administrative (root) control over the computer. This could allow an attacker to bypass security policies, access sensitive data, or disable the security agent entirely.

Technical details

An origin validation error exists within the TmSelfProtect component of the Trend Micro Apex One (mac) Security Agent. The vulnerability stems from insufficient validation of the origin of commands sent to the self-protection mechanism. A local attacker who has already obtained low-privileged code execution on the system can exploit this flaw to send unauthorized commands, leading to arbitrary code execution in the context of root. The issue was addressed in the SaaS 2507 and 2005 Yearly Release updates via ActiveUpdate.

Affected products

  • Trend Micro Apex One (mac) Security Agent SaaS 2507 and 2005 Yearly Release (and prior)

Timeline

  • 2025-04-08: disclosed: Vulnerability reported to vendor
  • 2025-07-01: patched: Addressed via SaaS 2507 and 2005 Yearly Release updates
  • 2026-03-03: advisory: Coordinated public release of advisory by ZDI
  • 2026-05-21: other: NVD publication date

References