CVE-2025-52521
7.8Trend Micro · Trend Micro Security (Consumer)
Trend Micro Security 17.8 is vulnerable to a local privilege escalation via link following, allowing a local attacker to delete critical files, including those belonging to the application itself.
Executive summary
A local privilege escalation vulnerability in Trend Micro Security 17.8 could allow an attacker to delete system files, resulting in a total loss of confidentiality, integrity, and availability.
Vulnerability
The software is susceptible to a local privilege escalation flaw involving Windows Shortcut (.LNK) file following, which allows an authenticated local attacker with low privileges to manipulate file operations.
Business impact
The ability for a local attacker to delete privileged files poses a significant risk to system stability and security. With a CVSS score of 7.8, this vulnerability is categorized as High severity, as it allows an attacker to potentially disable security features or compromise the host environment entirely. Unauthorized file deletion can lead to service outages and the removal of forensic evidence or security logs.
Remediation
Immediate Action: Update Trend Micro Security (Consumer) to version 17.8.1476 or later as specified in the vendor advisory.
Proactive Monitoring: Monitor system logs for unusual file deletion activity or the creation of suspicious shortcut files in directories accessible to low-privileged users.
Compensating Controls: Ensure that users operate with the principle of least privilege, limiting the ability of standard users to execute arbitrary code or interact with sensitive system paths.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high CVSS score and the potential for total system impact, organizations should prioritize the deployment of the vendor-provided update. Immediate application of the patch is necessary to prevent local attackers from exploiting this privilege escalation path to disrupt security operations or compromise the local environment.