Trend Micro Apex One Damage Cleanup Engine Link Following Local Privilege Escalation Vulnerability

Vulnerability

A link following vulnerability has been identified in the Trend Micro Apex One Damage Cleanup Engine, which could allow a local attacker to escalate privileges on affected installations. This vulnerability requires the attacker to first execute low-privileged code on the target system.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing a local attacker to execute arbitrary code with SYSTEM privileges on the affected system.

Remediation

Trend Micro has released a patch for this vulnerability in both Apex One and Apex One as a Service. Users can download the updated version of Apex One from the Trend Micro Download Center. For Apex One as a Service, the updated Security Agent version is available now.

Added: Jun 17, 2025, 7:24 PM
Updated: Jun 17, 2025, 9:07 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
7.5
exploitability
3.5
remediation
7.7
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.