Trend Micro Apex One and Vision One Origin Validation Vulnerability Allowing Local Privilege Escalation

Vulnerability

A vulnerability allowing origin validation errors in the Apex One/SEP agent could enable a local attacker to escalate privileges on affected systems. This vulnerability exists in Apex One 2019 (on-premise), Apex One as a Service, and TrendAI Vision One Endpoint Security - Standard Endpoint Protection (SEP) with agent builds prior to 14.0.20731. The vulnerability arises because the affected process protection mechanisms do not properly validate origins, allowing for unauthorized privilege escalation. To exploit this vulnerability, an attacker must first gain the ability to execute low-privileged code on the target system.

Impact

Exploitation of this vulnerability could lead to unauthorized privilege escalation, allowing a local attacker to gain elevated rights on the affected system.

Remediation

Users of Apex One (on-prem) should update to SP1 CP Build 18012 or SP1 Build 17079. For Apex One as a Service and TrendAI Vision One SEP users, the Security Agent build 14.0.20731 is available. Customers are encouraged to visit the Trend Micro Download Center to obtain the latest versions.

Added: May 21, 2026, 2:19 PM
Updated: May 21, 2026, 2:19 PM

Vulnerability Rating

Custom Algorithm
spread
0.3
impact
10.0
exploitability
3.5
remediation
7.7
relevance
8.5
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.