Trend Micro Apex One
cpe:2.3:a:trendmicro:apex_one:*:*:*:*:windows:*:*, +1 more
- 2019 (On-prem)
- SaaS
A local privilege escalation vulnerability has been identified in the Trend Micro Apex One Security Agent. This uncontrolled search path vulnerability allows local attackers to escalate privileges on affected installations. Exploitation requires the ability to execute low-privileged code on the target system. The vulnerability arises because the product uninstaller executes a program from an unsecured location, which an attacker can exploit to gain elevated privileges and execute arbitrary code with SYSTEM rights.
Exploitation of this vulnerability allows local attackers to escalate privileges, executing arbitrary code in the context of the SYSTEM user.
Trend Micro has released a patch for this vulnerability. Affected users can update to the latest version available through the Trend Micro Download Center.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.