Executive brief
Trend Micro Apex One and Vision One endpoint agents are security software used to protect corporate workstations and servers from malware. A vulnerability in these agents could allow a user who already has limited access to a computer to gain full administrative control. This could be used by an attacker to disable security protections or gain deeper access to the corporate network.
Technical details
An origin validation error (CWE-346) exists within the process protection communication mechanism of the Trend Micro Apex One and Vision One SEP agents. The vulnerability stems from insufficient verification of the source of inter-process communications. A local attacker with low-privileged code execution capabilities can exploit this flaw to bypass security checks and escalate their privileges to a higher level, such as SYSTEM. Patches have been released for both on-premise and SaaS versions of the affected products.
Affected products
- Trend Micro Apex One (on-prem) Agent Builds below 17079
- Trend Micro Apex One as a Service Agent Builds below 14.0.20731
- Trend Micro Vision One Endpoint Security - Standard Endpoint Protection (SEP) Agent Builds below 14.0.20731
Timeline
- 2026-05-21: disclosed
- 2026-05-21: advisory
- 2026-05-21: patched