CVE Database
/

CVE-2023-52094

Back to search

CVE-2023-52094

Published: Jan 23, 2024

Modified: Jun 20, 2025

PUBLISHED

Description

An updater link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to abuse the updater to delete an arbitrary folder, leading for a local privilege escalation on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

VendorProductVersions

Trend Micro, Inc.

Trend Micro Apex One

affected
2019 (14.0) - < 14.0.0.12534

Trend Micro, Inc.

Trend Micro Apex One as a Service

affected
SaaS - < 14.0.12849

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now