Trend Micro Apex One
cpe:2.3:a:trendmicro:apex_one:*:*:*:*:windows:*:*
- 2019 (On-prem)
- SaaS
A time-of-check time-of-use vulnerability has been identified in the cache mechanism of the Trend Micro Apex One (Mac) agent. This vulnerability could allow a local attacker to escalate privileges on affected installations. The issue arises from improper cache key validation during signature verification, enabling an attacker to gain elevated rights and execute arbitrary code with root privileges. To exploit this vulnerability, an attacker must first have the ability to run low-privileged code on the target system.
Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing a local attacker to execute code with elevated rights, potentially compromising the entire system.
Trend Micro has released a Critical Patch for Apex One (Mac) to address this vulnerability. More details can be found on the Trend Micro Success Portal.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.