Zero Day Initiative publishes three Trend Micro Apex One local privilege escalation advisories (ZDI-26-652, ZDI-26-653, ZDI-26-654)
ZDI published three advisories dated 2026-09-10 for local privilege escalation flaws in Trend Micro Apex One Security Agent: two TOCTOU race conditions in the cache mechanism (CVE-2025-71415, CVE-2025-71416) and one incomplete cleanup flaw (CVE-2025-71414),…
The Zero Day Initiative published three coordinated advisories covering local privilege escalation vulnerabilities in the Trend Micro Apex One Security Agent. ZDI-26-652 (CVE-2025-71416) and ZDI-26-653 (CVE-2025-71415) describe time-of-check time-of-use (TOCTOU) flaws in the Apex One cache mechanism, while ZDI-26-654 (CVE-2025-71414) covers an incomplete cleanup flaw. All three allow local attackers to escalate privileges after gaining low-privileged code execution, and ZDI rated all three CVSS 7.8. Vendor fixes/patches are available for affected installations. The three reports are consistent; no source disagreements were found.
- ZDI-26-652: TOCTOU flaw in the Apex One Security Agent cache mechanism, tracked as CVE-2025-71416, CVSS 7.8
- ZDI-26-653: TOCTOU flaw in the Apex One Security Agent cache mechanism, tracked as CVE-2025-71415, CVSS 7.8
- ZDI-26-654: Incomplete cleanup flaw in Trend Micro Apex One, tracked as CVE-2025-71414, CVSS 7.8
- All three flaws allow local privilege escalation and require prior low-privileged code execution
- Vendor fixes/patches are available for affected installations
- Disclosure was coordinated by the Zero Day Initiative, with the advisories published per reports dated 2026-09-10
Coverage timelineoldest first · each row is one article
- · 5d agoZDI-26-654: TrendAI Apex One Incomplete Cleanup Local Privilege Escalation Vulnerability
ZDI Published Advisories· 25
ZDI-26-654: Trend Micro Apex One incomplete cleanup flaw, CVE-2025-71414, enables local privilege escalation, rated CVSS 7.8.
- · 5d agoZDI-26-652: TrendAI Apex One Security Agent Cache Mechanism Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability
ZDI Published Advisories· 25
ZDI-26-652: TOCTOU race in Trend Micro Apex One cache mechanism, CVE-2025-71416, enables local privilege escalation, rated CVSS 7.8.
- · 5d agoZDI-26-653: TrendAI Apex One Security Agent Cache Mechanism Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability
ZDI Published Advisories· 25
ZDI-26-653: TOCTOU race in Trend Micro Apex One cache mechanism, CVE-2025-71415, enables local privilege escalation, rated CVSS 7.8.
Vulnerabilities in this storyAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2025-71414 | NVD description · AI analysis pending | — | — | — | — | — | |
| CVE-2025-71415 | NVD description · AI analysis pending | — | — | — | — | — | |
| CVE-2025-71416 | NVD description · AI analysis pending | — | — | — | — | — |