Junglewise Threat Intelligence

CVE-2026-45208: Trend Micro Apex One and Vision One SEP TOCTOU privilege escalation

CVE-2026-45208 · Severity: high · CVSS 7.8 · Published 2026-05-21

Technologies: Trend Micro Vision One Endpoint Security Agent, Trend Micro Apex One Agent, Trend Micro Apex One as a Service Agent. Vendors: Trend Micro.

Executive brief

Trend Micro Apex One and Vision One endpoint agents are used to protect corporate computers from malware and cyber threats. A vulnerability in these agents could allow a person who already has limited access to a computer to gain full administrative control. This could lead to the unauthorized access of sensitive data or the disabling of security protections on the affected machine.

Technical details

A time-of-check time-of-use (TOCTOU) race condition vulnerability (CWE-367) exists in the Trend Micro Apex One and Vision One Standard Endpoint Protection (SEP) agents for Windows. The flaw occurs when the agent checks a resource property before performing an action, but the resource is modified by a malicious process between the check and the use. An attacker who has already obtained low-privileged code execution on the target system can exploit this race condition to escalate their privileges to a higher level. Trend Micro has released patches for both on-premises and SaaS versions of the affected products to address this issue.

Affected products

  • Trend Micro Apex One (On-prem) Agent Below 17079
  • Trend Micro Apex One as a Service Agent Below 14.0.20731
  • Trend Micro Vision One Endpoint Security - Standard Endpoint Protection (SEP) Agent Below 14.0.20731

Timeline

  • 2026-05-21: disclosed
  • 2026-05-21: advisory
  • 2026-05-21: patched

References

Related threats