Trend Micro Apex One
cpe:2.3:a:trendmicro:apex_one:*:*:*:*:windows:*:*
- 2019 (On-prem)
- SaaS
A time-of-check time-of-use vulnerability has been identified in the Trend Micro Apex One (Mac) agent iCore service. This vulnerability allows local attackers to escalate privileges on affected installations by exploiting improper file path validation during signature verification. To successfully exploit this vulnerability, an attacker must first gain the ability to execute low-privileged code on the target system.
Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing a local attacker to execute arbitrary code with elevated rights, potentially in the context of the root user.
Trend Micro has released a Critical Patch for Apex One (Mac) to address this vulnerability. This update is available through the Trend Micro Download Center.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.