ZeroHour
ZDI Published Advisoriespublished ()ingested
Part of a story covered by 3 sources: “Zero Day Initiative publishes three Trend Micro Apex One local privilege escalation advisories (ZDI-26-652, ZDI-26-653, ZDI-26-654)” — merged summary and timeline →

ZDI-26-654: TrendAI Apex One Incomplete Cleanup Local Privilege Escalation Vulnerability

mediumAdvisoryimportance 25CVE-2025-71414
AI summary · glm-5.3-flash

ZDI-26-654: Trend Micro Apex One incomplete cleanup flaw, CVE-2025-71414, enables local privilege escalation, rated CVSS 7.8.

The Zero Day Initiative published advisory ZDI-26-654 for the Trend Micro Apex One Security Agent. An incomplete cleanup flaw, tracked as CVE-2025-71414, allows local attackers to escalate privileges after gaining low-privileged code execution. ZDI assigned a CVSS 7.8 rating. The advisory accompanies a vendor fix for affected installations.

  • Local privilege escalation in Trend Micro Apex One Security Agent
  • Tracked as CVE-2025-71414 with CVSS 7.8
  • Requires prior low-privileged code execution
  • Disclosure coordinated by the Zero Day Initiative
ProductsApex One
OrganizationsZero Day Initiative

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2025-71414

NVD description · AI analysis pending
Full article

This vulnerability allows local attackers to escalate privileges on affected installations of TrendAI Apex One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-71414.

This source does not provide full text. Read it at zerodayinitiative.com.