ZDI-26-654: TrendAI Apex One Incomplete Cleanup Local Privilege Escalation Vulnerability
ZDI-26-654: Trend Micro Apex One incomplete cleanup flaw, CVE-2025-71414, enables local privilege escalation, rated CVSS 7.8.
The Zero Day Initiative published advisory ZDI-26-654 for the Trend Micro Apex One Security Agent. An incomplete cleanup flaw, tracked as CVE-2025-71414, allows local attackers to escalate privileges after gaining low-privileged code execution. ZDI assigned a CVSS 7.8 rating. The advisory accompanies a vendor fix for affected installations.
- Local privilege escalation in Trend Micro Apex One Security Agent
- Tracked as CVE-2025-71414 with CVSS 7.8
- Requires prior low-privileged code execution
- Disclosure coordinated by the Zero Day Initiative
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-71414 | NVD description · AI analysis pending | — | — | — | — | — |
This vulnerability allows local attackers to escalate privileges on affected installations of TrendAI Apex One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-71414.
This source does not provide full text. Read it at zerodayinitiative.com.