Trend Micro Trend Vision One Broken Access Control Vulnerability Allowing Privilege Escalation
Vulnerability
A broken access control vulnerability in the Trend Vision One Role Name component could have permitted an administrator to create users with the ability to modify account roles, leading to unauthorized privilege escalation. This issue has been resolved on the backend service and is no longer active.
Impact
Exploitation of this vulnerability could have allowed for unauthorized privilege escalation by manipulating user roles.
Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
5.0exploitability
5.2remediation
0.0relevance
0.0threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
