CVE-2026-45208
Trend Micro Apex One Agent vulnerability analysis and mitigation

Overview

CVE-2026-45208 is a Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in the Trend Micro Apex One and Vision One – Standard Endpoint Protection (SEP) security agent that allows local attackers to escalate privileges to SYSTEM level. It was disclosed on May 21, 2026, as part of Trend Micro's May 2026 Security Bulletin, and a ZDI advisory (ZDI-26-326 / ZDI-CAN-27982) was published on May 28, 2026. Affected products include Apex One 2019 (on-premises) with agent builds below 14.0.0.17079 and Apex One as a Service / Vision One SEP with SaaS agent builds below 14.0.20731, both on Windows. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Trend Micro Advisory, GitHub Advisory).

Technical details

The vulnerability is classified as CWE-367 (Time-of-Check Time-of-Use Race Condition), residing specifically in the Apex One NT RealTime Scan service. The flaw arises from improper locking when performing operations on an object: the service checks the state of a resource and then uses it, but the resource's state can be altered by a low-privileged attacker in the window between the check and the use. By winning this race condition, an attacker can redirect or manipulate the object being operated on, causing the service — which runs with SYSTEM privileges — to execute attacker-controlled code. The vulnerability was discovered by researcher Lays (@_L4ys) of TRAPA Security working with the Trend Micro Zero Day Initiative (Trend Micro Advisory, ZDI Advisory).

Impact

Successful exploitation allows a local attacker with low-privileged code execution to escalate privileges and execute arbitrary code in the context of SYSTEM, achieving full control over the affected Windows endpoint. This results in high confidentiality, integrity, and availability impact — an attacker could access sensitive data, modify system files, disable security controls, or use the compromised endpoint as a pivot point for lateral movement within the network. Because the affected component is a security agent (Apex One/SEP), compromise could also undermine the integrity of the endpoint protection platform itself (Trend Micro Advisory, GitHub Advisory).

Exploitation steps

  1. Initial Access: Gain low-privileged code execution on a Windows system running a vulnerable version of the Trend Micro Apex One or Vision One SEP agent (on-premises agent build < 14.0.0.17079 or SaaS agent build < 14.0.20731). This could be achieved via phishing, exploitation of another vulnerability, or legitimate user-level access.
  2. Reconnaissance: Identify the presence of the Apex One NT RealTime Scan service (e.g., via sc query or tasklist) and confirm the installed agent version is vulnerable.
  3. Race Condition Setup: Craft a timing attack targeting the TOCTOU window in the NT RealTime Scan service. This involves monitoring or triggering the service's object check operation, then rapidly substituting or modifying the target object (e.g., via symbolic link manipulation or file/handle replacement) between the check and the use.
  4. Privilege Escalation: Win the race condition so that the SYSTEM-privileged service operates on the attacker-controlled object instead of the intended one, resulting in execution of attacker-supplied code or commands with SYSTEM privileges.
  5. Post-Exploitation: With SYSTEM-level access, deploy persistence mechanisms, exfiltrate data, disable security controls, or move laterally within the network (Trend Micro Advisory, ZDI Advisory).

Indicators of compromise

  • Process: Unexpected child processes spawned by the Apex One NT RealTime Scan service (e.g., cmd.exe, powershell.exe, or other shells) running under the SYSTEM account.
  • File System: New or modified files in system directories (e.g., C:\Windows\System32) created by the Apex One service account; unexpected executables or scripts placed in Apex One installation directories.
  • Logs: Windows Security Event Log entries showing privilege escalation (Event ID 4672 – Special privileges assigned to new logon) associated with unexpected processes; Windows System Event Log anomalies related to the Apex One NT RealTime Scan service.
  • Registry: Unexpected registry modifications under HKLM\SYSTEM or HKLM\SOFTWARE\TrendMicro made by low-privileged user accounts.
  • Network: Outbound connections from the Apex One service process to unexpected external IP addresses, potentially indicating post-exploitation C2 activity.

Mitigation and workarounds

Trend Micro has released patched versions to address CVE-2026-45208: for Apex One 2019 (on-premises), update to SP1 CP Build 18012 (for existing SP1 users) or SP1 Build 17079 (for new installs), ensuring at least agent build 14.0.0.17079; for Apex One as a Service and Vision One SEP, update to SaaS agent build 14.0.20731 or later. No configuration-based workaround is provided; patching is the only remediation. As a general mitigating measure, restrict local access to systems running the agent, review remote access policies, and ensure perimeter security is current. Trend Micro strongly encourages customers to apply the latest available build as soon as possible (Trend Micro Advisory).

Community reactions

The vulnerability was responsibly disclosed by Lays (@_L4ys) of TRAPA Security through the Trend Micro Zero Day Initiative program, and Trend Micro acknowledged the researcher in its May 2026 Security Bulletin (Trend Micro Advisory). The Belgium Centre for Cybersecurity (CCB) issued a warning about multiple vulnerabilities in TrendAI Apex One and Vision One SEP, including CVE-2026-45208. The broader bulletin attracted attention due to the in-the-wild exploitation of the related CVE-2026-34926 directory traversal vulnerability, which elevated urgency for the entire patch set. Coverage appeared across security news aggregators and vulnerability databases shortly after disclosure (ZDI Advisory).

Additional resources


SourceThis report was generated using AI

Related Trend Micro Apex One Agent vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-45208HIGH7.8
  • Trend Micro Apex One Agent logoTrend Micro Apex One Agent
  • cpe:2.3:a:trendmicro:apex_one
NoYesMay 21, 2026
CVE-2026-45207HIGH7.8
  • Trend Micro Apex One Agent logoTrend Micro Apex One Agent
  • cpe:2.3:a:trendmicro:apex_one
NoYesMay 21, 2026
CVE-2026-45206HIGH7.8
  • Trend Micro Apex One Agent logoTrend Micro Apex One Agent
  • cpe:2.3:a:trendmicro:apex_one
NoYesMay 21, 2026
CVE-2026-34930HIGH7.8
  • Trend Micro Apex One Agent logoTrend Micro Apex One Agent
  • cpe:2.3:a:trendmicro:apex_one
NoYesMay 21, 2026
CVE-2026-34929HIGH7.8
  • Trend Micro Apex One Agent logoTrend Micro Apex One Agent
  • cpe:2.3:a:trendmicro:apex_one
NoYesMay 21, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management