Junglewise Threat Intelligence

CVE-2026-45207: Trend Micro Apex One and Vision One privilege escalation in Security Agent

CVE-2026-45207 · Severity: high · CVSS 7.8 · Published 2026-05-21

Technologies: Trend Micro Apex One Agent, Trend Micro Apex One as a Service Agent, Trend Micro Vision One Endpoint Security - Standard Endpoint Protection (SEP) Agent, Trend Micro Vision One Endpoint Security - Standard Endpoint Protection Agent. Vendors: Trend Micro.

Executive brief

A vulnerability in the Trend Micro Apex One and Vision One endpoint security agents could allow a user with limited access to a computer to gain full administrative control. These agents are security software used to protect corporate laptops and servers from malware and cyberattacks. If exploited, an attacker who already has a foothold on a system could bypass security protections to install malicious software or access sensitive data.

Technical details

An origin validation error (CWE-346) exists within the process protection communication mechanism of the Trend Micro Apex One and Vision One Standard Endpoint Protection (SEP) agents. The vulnerability stems from insufficient verification of the source of inter-process communications. A local attacker with low-privileged code execution capabilities can exploit this flaw to bypass security controls and escalate their privileges to a higher level. This specific issue is part of a series of similar vulnerabilities affecting different communication channels, such as named pipes and other IPC mechanisms. Patches are available in Apex One (on-prem) Agent build 17079 and SaaS Agent build 14.0.20731.

Affected products

  • Trend Micro Apex One (On-prem) Agent Builds below 17079
  • Trend Micro Apex One as a Service Agent Builds below 14.0.20731
  • Trend Micro Vision One Endpoint Security - Standard Endpoint Protection (SEP) Agent Builds below 14.0.20731

Timeline

  • 2026-05-21: disclosed
  • 2026-05-21: advisory
  • 2026-05-21: patched

References

Related threats