
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-45208 is a Time-of-Check Time-of-Use (TOCTOU) race condition vulnerability in the Trend Micro Apex One and Vision One – Standard Endpoint Protection (SEP) security agent that allows local attackers to escalate privileges to SYSTEM level. It was disclosed on May 21, 2026, as part of Trend Micro's May 2026 Security Bulletin, and a ZDI advisory (ZDI-26-326 / ZDI-CAN-27982) was published on May 28, 2026. Affected products include Apex One 2019 (on-premises) with agent builds below 14.0.0.17079 and Apex One as a Service / Vision One SEP with SaaS agent builds below 14.0.20731, both on Windows. The vulnerability carries a CVSS v3.1 base score of 7.8 (High) (Trend Micro Advisory, GitHub Advisory).
The vulnerability is classified as CWE-367 (Time-of-Check Time-of-Use Race Condition), residing specifically in the Apex One NT RealTime Scan service. The flaw arises from improper locking when performing operations on an object: the service checks the state of a resource and then uses it, but the resource's state can be altered by a low-privileged attacker in the window between the check and the use. By winning this race condition, an attacker can redirect or manipulate the object being operated on, causing the service — which runs with SYSTEM privileges — to execute attacker-controlled code. The vulnerability was discovered by researcher Lays (@_L4ys) of TRAPA Security working with the Trend Micro Zero Day Initiative (Trend Micro Advisory, ZDI Advisory).
Successful exploitation allows a local attacker with low-privileged code execution to escalate privileges and execute arbitrary code in the context of SYSTEM, achieving full control over the affected Windows endpoint. This results in high confidentiality, integrity, and availability impact — an attacker could access sensitive data, modify system files, disable security controls, or use the compromised endpoint as a pivot point for lateral movement within the network. Because the affected component is a security agent (Apex One/SEP), compromise could also undermine the integrity of the endpoint protection platform itself (Trend Micro Advisory, GitHub Advisory).
sc query or tasklist) and confirm the installed agent version is vulnerable.cmd.exe, powershell.exe, or other shells) running under the SYSTEM account.C:\Windows\System32) created by the Apex One service account; unexpected executables or scripts placed in Apex One installation directories.HKLM\SYSTEM or HKLM\SOFTWARE\TrendMicro made by low-privileged user accounts.Trend Micro has released patched versions to address CVE-2026-45208: for Apex One 2019 (on-premises), update to SP1 CP Build 18012 (for existing SP1 users) or SP1 Build 17079 (for new installs), ensuring at least agent build 14.0.0.17079; for Apex One as a Service and Vision One SEP, update to SaaS agent build 14.0.20731 or later. No configuration-based workaround is provided; patching is the only remediation. As a general mitigating measure, restrict local access to systems running the agent, review remote access policies, and ensure perimeter security is current. Trend Micro strongly encourages customers to apply the latest available build as soon as possible (Trend Micro Advisory).
The vulnerability was responsibly disclosed by Lays (@_L4ys) of TRAPA Security through the Trend Micro Zero Day Initiative program, and Trend Micro acknowledged the researcher in its May 2026 Security Bulletin (Trend Micro Advisory). The Belgium Centre for Cybersecurity (CCB) issued a warning about multiple vulnerabilities in TrendAI Apex One and Vision One SEP, including CVE-2026-45208. The broader bulletin attracted attention due to the in-the-wild exploitation of the related CVE-2026-34926 directory traversal vulnerability, which elevated urgency for the entire patch set. Coverage appeared across security news aggregators and vulnerability databases shortly after disclosure (ZDI Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."