CVE-2026-34930
Trend Micro Apex One Agent vulnerability analysis and mitigation

Overview

CVE-2026-34930 is a local privilege escalation vulnerability (Origin Validation Error) in the Trend Micro Apex One and Vision One Standard Endpoint Protection (SEP) Security Agent, specifically within a process protection mechanism of the Apex One NT Listener service. Discovered and disclosed on May 21, 2026, it affects Apex One on-premises agent builds below 14.0.0.17079 and Apex One as a Service / Vision One SEP SaaS agent builds below 14.0.20731, both on Windows. It is one of several related CVEs (CVE-2026-34927 through CVE-2026-34930) reported by researcher Lays (@_L4ys) of TRAPA Security via the Zero Day Initiative. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Trend Micro Advisory, GitHub Advisory).

Technical details

The root cause is classified as CWE-346 (Origin Validation Error): the Apex One/SEP Security Agent's process protection mechanism fails to sufficiently validate the origin of commands it receives, allowing a local attacker to send crafted commands that are accepted as legitimate. This is analogous to CVE-2026-34927, CVE-2026-34928, and CVE-2026-34929, which exploit similar origin validation flaws in different IPC mechanisms (named pipes, inter-process communication, and process protection), with CVE-2026-34930 specifically targeting a distinct process protection mechanism (ZDI-CAN-28089). Exploitation requires the attacker to already have low-privileged code execution on the target Windows system; no network access or user interaction is needed beyond that initial foothold (Trend Micro Advisory, ZDI Advisory).

Impact

Successful exploitation allows a local attacker with low privileges to escalate to SYSTEM-level privileges and execute arbitrary code in the context of the SYSTEM account on the affected Windows endpoint. This grants full control over the compromised host, including access to all data, the ability to disable security controls, install persistent backdoors, and potentially pivot to other systems on the network. Confidentiality, integrity, and availability are all rated as High impact (Trend Micro Advisory, GitHub Advisory).

Exploitation steps

  1. Initial Access: Obtain low-privileged code execution on a Windows system running a vulnerable version of the Trend Micro Apex One or Vision One SEP Security Agent (on-premises agent build < 14.0.0.17079 or SaaS agent build < 14.0.20731).
  2. Reconnaissance: Identify the presence of the Apex One NT Listener service and its associated process protection mechanism on the target system (e.g., via sc query or process enumeration).
  3. Craft Malicious Command: Prepare a command or message that exploits the insufficient origin validation in the process protection mechanism, spoofing a trusted source to have the privileged service accept and execute the command.
  4. Send Crafted Command: Deliver the crafted command to the vulnerable process protection mechanism of the Apex One NT Listener service from the low-privileged context.
  5. Privilege Escalation: The service, failing to validate the command's origin, processes the attacker-controlled input and executes arbitrary code in the SYSTEM context, granting the attacker full SYSTEM-level privileges on the host (Trend Micro Advisory, ZDI Advisory).

Indicators of compromise

  • Process: Unexpected child processes spawned by the Apex One NT Listener service or related Apex One agent processes running under the SYSTEM account (e.g., cmd.exe, powershell.exe, or other shells).
  • Logs: Windows Security Event Log entries showing privilege escalation (Event ID 4672 – Special privileges assigned to new logon) originating from Apex One service accounts unexpectedly; unusual process creation events (Event ID 4688) with SYSTEM-level tokens spawned from Apex One agent processes.
  • File System: New or modified files in Apex One installation directories or system directories created by SYSTEM-level processes that are not part of normal Apex One operations; unexpected scheduled tasks or services created under SYSTEM context.
  • Network: Outbound connections from the endpoint to unknown external IPs initiated by SYSTEM-level processes associated with Apex One agent binaries, which may indicate post-exploitation activity.

Mitigation and workarounds

Trend Micro has released patches addressing CVE-2026-34930 and related vulnerabilities. For Apex One on-premises, update to SP1 CP Build 18012 (for existing SP1 users) or SP1 Build 17079 (for new installs), ensuring the agent is at least build 14.0.0.17079. For Apex One as a Service and Vision One SEP, update the Security Agent to build 14.0.20731 or later. As a general mitigating factor, restrict local user access to affected systems and review remote access policies. Trend Micro strongly encourages immediate patching, especially given active exploitation of a related vulnerability (CVE-2026-34926) in the same bulletin (Trend Micro Advisory).

Community reactions

The Belgium Centre for Cybersecurity (CCB) issued a warning regarding multiple vulnerabilities in TrendAI Apex One and Vision One SEP, including CVE-2026-34930, noting active exploitation concerns in the broader bulletin (CCB Advisory). Japan's JVN and JVNDB also published advisories covering the vulnerability cluster. The Zero Day Initiative published advisory ZDI-26-323 covering CVE-2026-34930, credited to researcher Lays (@_L4ys) of TRAPA Security (ZDI Advisory). Community discussion has been limited, with no significant social media controversy, though the bulletin's ITW exploitation notice for CVE-2026-34926 has drawn attention to the entire vulnerability set.

Additional resources


SourceThis report was generated using AI

Related Trend Micro Apex One Agent vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45208HIGH7.8
  • Trend Micro Apex One Agent logoTrend Micro Apex One Agent
  • cpe:2.3:a:trendmicro:apex_one
NoYesMay 21, 2026
CVE-2026-45207HIGH7.8
  • Trend Micro Apex One Agent logoTrend Micro Apex One Agent
  • cpe:2.3:a:trendmicro:apex_one
NoYesMay 21, 2026
CVE-2026-45206HIGH7.8
  • Trend Micro Apex One Agent logoTrend Micro Apex One Agent
  • cpe:2.3:a:trendmicro:apex_one
NoYesMay 21, 2026
CVE-2026-34930HIGH7.8
  • Trend Micro Apex One Agent logoTrend Micro Apex One Agent
  • cpe:2.3:a:trendmicro:apex_one
NoYesMay 21, 2026
CVE-2026-34929HIGH7.8
  • Trend Micro Apex One Agent logoTrend Micro Apex One Agent
  • cpe:2.3:a:trendmicro:apex_one
NoYesMay 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management