ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 3 sources: “Zero Day Initiative publishes three Trend Micro Apex One local privilege escalation advisories (ZDI-26-652, ZDI-26-653, ZDI-26-654)” — merged summary and timeline →

ZDI-26-652: TrendAI Apex One Security Agent Cache Mechanism Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability

mediumAdvisoryimportance 25CVE-2025-71416
AI summary · glm-5.3-flash

ZDI-26-652: TOCTOU race in Trend Micro Apex One cache mechanism, CVE-2025-71416, enables local privilege escalation, rated CVSS 7.8.

The Zero Day Initiative published advisory ZDI-26-652 for the Trend Micro Apex One Security Agent. A time-of-check time-of-use (TOCTOU) flaw in the cache mechanism, tracked as CVE-2025-71416, allows local attackers to escalate privileges after gaining low-privileged code execution. ZDI assigned a CVSS 7.8 rating. A vendor patch is available for affected installations.

  • TOCTOU flaw in Apex One cache mechanism allows privilege escalation
  • Tracked as CVE-2025-71416 with CVSS 7.8
  • Requires prior low-privileged code execution
  • Disclosure coordinated by the Zero Day Initiative
ProductsApex One
OrganizationsZero Day Initiative

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-71416

NVD description · AI analysis pending
Full article

This vulnerability allows local attackers to escalate privileges on affected installations of TrendAI Apex One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-71416.

This source does not provide full text. Read it at zerodayinitiative.com.