Executive brief
Trend Micro Apex One and Vision One endpoint agents are used to protect corporate computers from malware and cyber threats. A vulnerability in how these agents verify the source of internal requests could allow a user with limited access to gain full administrative control over the system. This could lead to the unauthorized access of sensitive data or the disabling of security protections on the affected machine.
Technical details
An origin validation error (CWE-346) exists within the process protection mechanism of the Trend Micro Apex One and Vision One SEP agents. The vulnerability stems from insufficient verification of the source of inter-process communications or requests. To exploit this, an attacker must already have the ability to execute low-privileged code on the target Windows system. Successful exploitation allows the attacker to bypass process protections and escalate their privileges to a higher level, potentially gaining full system control. Patches have been released for both on-premises and SaaS versions of the affected products.
Affected products
- Trend Micro Apex One (on-prem) Security Agent Builds below 17079
- Trend Micro Apex One as a Service Security Agent Builds below 14.0.20731
- Trend Micro Vision One Endpoint Security - Standard Endpoint Protection (SEP) Agent Builds below 14.0.20731
Timeline
- 2026-05-21: disclosed
- 2026-05-21: advisory: Trend Micro published security bulletin KA-0023430