Executive brief
Trend Micro Apex One and Vision One endpoint agents are affected by a security flaw that could allow a user with limited access to gain full administrative control over a computer. These agents are security software used to protect corporate laptops and servers from malware and cyberattacks. To exploit this, an attacker must already have the ability to run basic commands on the target machine, but once successful, they could bypass security controls or access sensitive data.
Technical details
An origin validation vulnerability (CWE-346) exists within the named pipe communication mechanism of the Trend Micro Apex One and Vision One Standard Endpoint Protection (SEP) agents. The flaw stems from insufficient verification of the source of inter-process communications. A local attacker who has already achieved low-privileged code execution on a Windows system can exploit this vulnerability to communicate with the agent's named pipes and escalate their privileges to a higher level. Trend Micro has released patches for both on-premise (Build 17079/18012) and SaaS (Build 14.0.20731) versions to address this issue.
Affected products
- Trend Micro Apex One (on-prem) Agent Builds below 17079
- Trend Micro Apex One as a Service Agent Builds below 14.0.20731
- Trend Micro Vision One Endpoint Security - Standard Endpoint Protection (SEP) Agent Builds below 14.0.20731
Timeline
- 2026-05-21: disclosed
- 2026-05-21: advisory
- 2026-05-21: patched