Security Advisory

CVE-2023-52094

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2024-01-23 20:40:30
Last updated 2025-06-20 18:56:24
Assigner trendmicro
State PUBLISHED

Description

An updater link following vulnerability in the Trend Micro Apex One agent could allow a local attacker to abuse the updater to delete an arbitrary folder, leading for a local privilege escalation on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.