ZDI-26-324: TrendAI Vision One Security Agent Origin Validation Error Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of TrendAI Vision One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-45206.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-324?
ZDI-26-324 has a CVSS rating of 46, indicating a moderate risk for local privilege escalation.
How do I fix ZDI-26-324?
To mitigate ZDI-26-324, ensure that your TrendAI Vision One Security Agent is updated to the latest version provided by Trend Micro.
Who is affected by ZDI-26-324?
ZDI-26-324 affects users of the TrendAI Vision One Security Agent who have not implemented necessary security measures.
What type of attack does ZDI-26-324 enable?
ZDI-26-324 enables local attackers to escalate privileges after gaining the ability to execute low-privileged code.
Can remote attackers exploit ZDI-26-324?
ZDI-26-324 requires local access to the system, so it cannot be exploited by remote attackers.