ZDI-26-143: Trend Micro Apex One Security Agent TmSelfProtect Origin Validation Error Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro Apex One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the TmSelfProtect component. The issue results from insufficient validation of the origin of commands. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root.
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro Apex One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-71217.
— ZDI
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Trend Micro Apex One Security Agent (TmSelfProtect)to a version that resolves this vulnerability.Patch ZDI-26-143 - Compensating control
Mitigate local exploitation preconditions by restricting/monitoring low-privileged execution on affected systems (least privilege for local users and prevent untrusted users/processes from executing code on the host).
- Operational
If there is any suspicion of exploitation, rotate any credentials or tokens that could be accessible to an attacker after privilege escalation, and review/collect host logs for indicators of compromise.
Event History
Frequently Asked Questions
What is the severity of ZDI-26-143?
ZDI-26-143 is classified as a high-severity vulnerability due to its ability to allow local privilege escalation.
How do I fix ZDI-26-143?
To fix ZDI-26-143, update the Trend Micro Apex One Security Agent to the latest version provided by Trend Micro.
Who is affected by ZDI-26-143?
ZDI-26-143 affects installations of Trend Micro Apex One Security Agent on systems where an attacker has local access.
What type of attack does ZDI-26-143 enable?
ZDI-26-143 enables local privilege escalation attacks by allowing attackers to gain elevated privileges on affected systems.
Is there a workaround for ZDI-26-143?
There are no known effective workarounds for ZDI-26-143; patching the software is recommended.