← All Advisories

Trend Micro Apex One for Mac self-protection origin validation flaw allows local privilege escalation

Last refreshed2026-09-30

Status: UPDATED  |  Advisory ID: CVE-2025-71217

Key Details

CVECVE-2025-71217
CVSS Score / Version7.8 (High) / CVSS v3.1
Updated2026-07-23
CVSS VectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is local; attack complexity is low; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productstrendmicro apex_one
Classified asCWE-346 (Origin Validation Error)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
trendmicroapex_one
SubsystemsGeneral OT
SectorsMultiple

What to Know

An origin validation error vulnerability in the Trend Micro Apex One (mac) agent self-protection mechanism could allow a local attacker to escalate privileges on affected installations.

Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

The following information is provided as informational only for CVE references, as these were addressed already via ActiveUpdate/SaaS updates in mid to late 2025 (SaaS 2507 & 2005 Yearly Release). (NVD)

What to Do

Monitor trendmicro's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2025-71217
CVEhttps://www.cve.org/CVERecord?id=CVE-2025-71217
Vendor advisoryhttps://success.trendmicro.com/en-US/solution/KA-0022458