ZDI-26-326: TrendAI Vision One Security Agent Time-Of-Check Time-Of-Use Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of TrendAI Vision One Security Agent. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-45208.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-326?
The severity of ZDI-26-326 is rated at 46 according to the CVSS framework.
How do I fix ZDI-26-326?
To fix ZDI-26-326, users should update the Trend Micro TrendAI Vision One Security Agent to the latest version provided by the vendor.
What type of vulnerability is ZDI-26-326?
ZDI-26-326 is a local privilege escalation vulnerability that allows attackers to gain higher access levels on affected systems.
Who is affected by ZDI-26-326?
Users of Trend Micro TrendAI Vision One Security Agent are affected by the ZDI-26-326 vulnerability.
What is the prerequisite for exploiting ZDI-26-326?
An attacker must first have the capability to execute low-privileged code on the target system to exploit ZDI-26-326.