Executive brief
Trend Micro Apex One and Vision One endpoint agents are security software used to protect corporate laptops and servers from malware. A vulnerability in these agents could allow a user who already has limited access to a computer to gain full administrative control. This could be used by an attacker to disable security protections or steal sensitive data from the affected machine.
Technical details
An origin validation error (CWE-346) exists in the Trend Micro Apex One and Vision One Standard Endpoint Protection (SEP) agents. The vulnerability stems from insufficient verification of the source of inter-process communications or requests. To exploit this, an attacker must first have the ability to execute low-privileged code on the target Windows system. Successful exploitation allows the attacker to bypass security boundaries and escalate privileges to a higher level, potentially SYSTEM. Trend Micro has released patches for both on-premises and SaaS versions of the affected products to address this issue.
Affected products
- Trend Micro Apex One (On-prem) Agent Below 17079
- Trend Micro Apex One as a Service Agent Below 14.0.20731
- Trend Micro Vision One Endpoint Security - Standard Endpoint Protection (SEP) Agent Below 14.0.20731
Timeline
- 2026-05-21: disclosed
- 2026-05-21: advisory
- 2026-05-21: patched