CVE-2026-45207
Trend Micro Apex One Agent vulnerability analysis and mitigation

Overview

CVE-2026-45207 is a local privilege escalation vulnerability (Origin Validation Error) in the Trend Micro Apex One and Vision One – Standard Endpoint Protection (SEP) Security Agent. The flaw exists within the Apex One NT Listener service, which fails to sufficiently validate the origin of commands, allowing a low-privileged local attacker to escalate to SYSTEM-level code execution. It affects Apex One 2019 (on-premises) agent builds below 14.0.0.17079 and Apex One as a Service / Vision One SEP SaaS agent builds below 14.0.20731, on Windows. Disclosed on May 21, 2026, it carries a CVSS v3.1 base score of 7.8 (High) (Trend Micro Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-346 (Origin Validation Error): the Apex One NT Listener service does not properly verify that the source of commands or inter-process communications is legitimate, allowing a low-privileged process to send commands that are accepted as if they originated from a trusted source. This is one of several related origin validation flaws (ZDI-CAN-29177) discovered in different process protection communication mechanisms within the same agent, similar to CVE-2026-45206 but affecting a distinct IPC channel. Exploitation requires the attacker to already have the ability to execute low-privileged code on the target Windows system; no network access or user interaction is needed beyond that initial foothold (Trend Micro Advisory, ZDI Advisory).

Impact

Successful exploitation allows a local attacker with low-privileged code execution to escalate privileges and execute arbitrary code in the context of the SYSTEM account, achieving complete control over the affected Windows endpoint. This grants full confidentiality, integrity, and availability impact — an attacker could exfiltrate sensitive data, install persistent malware, disable security controls, or use the compromised SYSTEM context as a pivot point for lateral movement within the network (Trend Micro Advisory, GitHub Advisory).

Mitigation and workarounds

Trend Micro has released patched builds addressing this vulnerability. For Apex One 2019 (on-premises), update to SP1 CP Build 18012 (for existing SP1 users) or SP1 Build 17079 (for new installs), ensuring the agent build is at least 14.0.0.17079. For Apex One as a Service and Vision One SEP, update the Security Agent to build 14.0.20731 or later. Trend Micro strongly encourages customers to apply the latest available build as soon as possible, and also advises reviewing remote access policies and perimeter security controls to limit attacker access to vulnerable machines (Trend Micro Advisory).

Community reactions

The vulnerability was responsibly disclosed by Lays (@_L4ys) of TRAPA Security through the Trend Micro Zero Day Initiative program and was part of a broader May 2026 security bulletin addressing eight vulnerabilities across Apex One and Vision One SEP. The Belgium Centre for Cybersecurity (CCB) issued a warning advisory covering the multiple vulnerabilities in this bulletin (Trend Micro Advisory). Community reaction has been limited, consistent with the low EPSS score and absence of public exploit code.

Additional resources


SourceThis report was generated using AI

Related Trend Micro Apex One Agent vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45208HIGH7.8
  • Trend Micro Apex One Agent logoTrend Micro Apex One Agent
  • cpe:2.3:a:trendmicro:apex_one
NoYesMay 21, 2026
CVE-2026-45207HIGH7.8
  • Trend Micro Apex One Agent logoTrend Micro Apex One Agent
  • cpe:2.3:a:trendmicro:apex_one
NoYesMay 21, 2026
CVE-2026-45206HIGH7.8
  • Trend Micro Apex One Agent logoTrend Micro Apex One Agent
  • cpe:2.3:a:trendmicro:apex_one
NoYesMay 21, 2026
CVE-2026-34930HIGH7.8
  • Trend Micro Apex One Agent logoTrend Micro Apex One Agent
  • cpe:2.3:a:trendmicro:apex_one
NoYesMay 21, 2026
CVE-2026-34929HIGH7.8
  • Trend Micro Apex One Agent logoTrend Micro Apex One Agent
  • cpe:2.3:a:trendmicro:apex_one
NoYesMay 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management