Trend Micro Apex One Link Following Local Privilege Escalation Vulnerability

Vulnerability

A local privilege escalation vulnerability has been identified in the Trend Micro Apex One scan engine. This vulnerability allows a local attacker to escalate privileges on affected installations by exploiting a link following flaw within the Virus Scan Engine. An attacker must first have the ability to execute low-privileged code on the target system to exploit this issue. The vulnerability exists in Trend Micro Apex One 2019 (On-prem) for Windows, as well as in Apex One as a Service and Trend Vision One Endpoint - Standard Endpoint Protection, both on Windows.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing a local attacker to execute arbitrary code with SYSTEM privileges on the affected machine.

Remediation

Trend Micro has released a Critical Patch for Apex One 2019 (On-prem) users, available for download from the Trend Micro Download Center. For Apex One as a Service and Trend Vision One Endpoint - Standard Endpoint Protection users, the update has been applied automatically.

Added: May 21, 2026, 2:33 PM
Updated: May 21, 2026, 2:33 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
2.5
exploitability
3.5
remediation
7.7
relevance
8.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.