Horizon Alert
Summary of the vulnerability and why it matters
A local attacker could potentially escalate privileges on Trend Micro Apex One installations by exploiting a time-of-check time-of-use vulnerability within the iCore service's signature verification. This flaw could allow unauthorized access and control over affected systems. The issue has been addressed through Trend Micro's ActiveUpdate and SaaS updates.
- Vulnerable component: Trend Micro Apex One agent iCore service.
- Core weakness: Signature verification flaw.
- Main business impact: Local privilege escalation.
Attack Path
How an attacker could exploit the issue
A local attacker with low-privileged code execution capabilities can exploit a time-of-check time-of-use vulnerability. This vulnerability exists in the Trend Micro Apex One agent's iCore service signature verification. Successful exploitation allows the attacker to escalate privileges on affected installations.
- Local low-privileged code execution required.
- Attacker verifies signature, then triggers use.
- Attacker achieves privilege escalation.
Live Threat
Current exploitation, exposure, and threat context
This vulnerability could allow a local attacker to elevate their privileges on an affected system. Successful exploitation would require the attacker to already have the ability to execute low-privileged code on the target machine. The potential damage includes unauthorized access and modification of data, impacting system integrity and confidentiality. While Trend Micro addressed this vulnerability via updates in mid to late 2025, organizations should ensure their systems have received these.
- Attacker skill level: Advanced
- Required access: Local code execution
- Business risk: Significant if unpatched
Priority actions
Operational Fix
Recommended remediation, mitigation, and detection steps
A local attacker with low-privileged code execution can escalate privileges on affected Trend Micro Apex One (mac) agent installations. This vulnerability requires an attacker to first gain initial access to the target system. Affected organizations should take action to identify and mitigate risks associated with this vulnerability.
- Find affected assets.
- Reduce exposure or isolate risk.
- Fix, verify, and monitor.