Executive brief
Trend Micro Apex One and Vision One endpoint agents are used to protect corporate computers from malware and cyber threats. A vulnerability in these agents could allow a person who already has limited access to a computer to gain full administrative control. This could lead to the unauthorized access of sensitive data or the disabling of security protections on the affected machine.
Technical details
A time-of-check time-of-use (TOCTOU) race condition vulnerability (CWE-367) exists in the Trend Micro Apex One and Vision One Standard Endpoint Protection (SEP) agents for Windows. The flaw occurs when the agent checks a resource property before performing an action, but the resource is modified by a malicious process between the check and the use. An attacker who has already obtained low-privileged code execution on the target system can exploit this race condition to escalate their privileges to a higher level. Trend Micro has released patches for both on-premises and SaaS versions of the affected products to address this issue.
Affected products
- Trend Micro Apex One (On-prem) Agent Below 17079
- Trend Micro Apex One as a Service Agent Below 14.0.20731
- Trend Micro Vision One Endpoint Security - Standard Endpoint Protection (SEP) Agent Below 14.0.20731
Timeline
- 2026-05-21: disclosed
- 2026-05-21: advisory
- 2026-05-21: patched