Junglewise Threat Intelligence

CVE-2026-34929: Trend Micro Apex One origin validation privilege escalation in IPC

CVE-2026-34929 · Severity: high · CVSS 7.8 · Published 2026-05-21

Technologies: Trend Micro Apex One Agent, Trend Micro Apex One as a Service Agent, Trend Micro Vision One Endpoint Security - Standard Endpoint Protection (SEP) Agent, Trend Micro Vision One Endpoint Security - Standard Endpoint Protection Agent. Vendors: Trend Micro.

Executive brief

A vulnerability in the Trend Micro Apex One and Vision One security agents could allow a user with limited access to a computer to gain full administrative control. These agents are used to protect corporate laptops and servers from malware and other cyber threats. If exploited, an attacker who has already gained a foothold on a system could bypass security restrictions to steal sensitive data or disable security software.

Technical details

An origin validation error (CWE-346) exists within the inter-process communication (IPC) mechanism of the Trend Micro Apex One and Vision One Standard Endpoint Protection (SEP) agents. The vulnerability stems from insufficient verification of the source of IPC requests, allowing a local attacker who has already obtained low-privileged code execution to send crafted messages to the agent. By exploiting this flaw, the attacker can achieve local privilege escalation (LPE) on the affected Windows installation. Trend Micro has released patches for both on-premises and SaaS versions of the product to address this issue.

Affected products

  • Trend Micro Apex One (on-prem) Agent Builds below 17079
  • Trend Micro Apex One as a Service Agent Builds below 14.0.20731
  • Trend Micro Vision One Endpoint Security - Standard Endpoint Protection (SEP) Agent Builds below 14.0.20731

Timeline

  • 2026-05-21: disclosed
  • 2026-05-21: advisory
  • 2026-05-21: patched

References

Related threats