CVE-2026-45208

7.8

Trend Micro · TrendAI Apex One

A TOCTOU race condition in the TrendAI Apex One agent allows a local attacker to escalate privileges.

Executive summary

A local privilege escalation vulnerability in the TrendAI Apex One agent poses a significant security risk by allowing attackers to gain elevated system permissions.

Vulnerability

This vulnerability is a time-of-check time-of-use (TOCTOU) race condition in the agent's processing. It requires the attacker to have local access and low privileges on the host system to successfully trigger the escalation.

Business impact

Successful exploitation of this flaw allows a local user to escalate privileges to a higher level, potentially gaining administrative control over the host. Given the CVSS score of 7.8, this represents a High severity risk, as it could lead to full system compromise, data theft, or the disabling of security software on the endpoint.

Remediation

Immediate Action: Update on-premises installations of TrendAI Apex One to version 14.0.0.17079 or later; SaaS users should ensure their agents are updated to 14.0.20731.

Proactive Monitoring: Monitor endpoint logs for suspicious process execution patterns or unexpected changes to local system configuration files.

Compensating Controls: Restrict local user access and ensure that standard user accounts do not have unnecessary permissions that could facilitate the exploitation of local race conditions.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

This vulnerability is a significant threat to endpoint integrity. Organizations should prioritize patching TrendAI Apex One agents across their environment to eliminate the potential for local privilege escalation.

More Trend Micro CVEs