Trend Micro Trend Vision One Broken Access Control Vulnerability Allowing Privilege Escalation

Vulnerability

A broken access control vulnerability in the Trend Vision One User Account component could have permitted an administrator to create users who could subsequently alter account roles and escalate privileges. This issue has been resolved on the backend service and is no longer active.

Impact

Exploitation of this vulnerability could have led to unauthorized privilege escalation by allowing users to change account roles and gain elevated rights.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
5.2
remediation
0.0
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.