7.8
CVE-2026-34928
- EPSS 0.21%
- Veröffentlicht 21.05.2026 13:03:39
- Zuletzt bearbeitet 23.07.2026 16:10:00
- Erkennungen
An origin validation vulnerability in the Apex One/SEP agent could allow a local attacker to escalate privileges on affected installations. This is similar to CVE-2026-34927 but exists in a different named pipe communication mechanism. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Trendmicro ≫ Apex One SwEdition on-premises SwPlatform windows Version < 14.0.0.17079
Trendmicro ≫ Apex One SwEdition saas SwPlatform windows Version < 14.0.20731
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.21% | 0.115 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| Trendmicro | 7.8 | 1.8 | 5.9 |
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
|
CWE-346 Origin Validation Error
The product does not properly verify that the source of data or communication is valid.
https://success.trendmicro.com/en-US/solution/KA-0023430