Tracked as
CVE-2020-24557 (CVSS 7.8), the high-severity vulnerability was patched in August last year after researchers with Trend Micro’s Zero Day Initiative explained that prior access to a vulnerable system is required for successful exploitation of the bug.
“This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro Apex One. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability,” the researchers said.
The security issue impacts ApexOne Security Agent’s logic that provides control over access to the Misc folder and could result in an attacker being able to execute code in the context of SYSTEM.