VYPR
Unrated severityNVD Advisory· Published Jun 26, 2023· Updated Dec 4, 2024

CVE-2023-32555

CVE-2023-32555

Description

A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations.

Please note: a local attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

This is similar to, but not identical to CVE-2023-32554.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A time-of-check time-of-use flaw in Trend Micro Apex One agent allows local privilege escalation to SYSTEM.

Vulnerability

A time-of-check time-of-use (TOCTOU) vulnerability exists in the Trend Micro Apex One and Apex One as a Service agent, specifically within the Apex One Client Plug-in Service Manager. The issue results from the lack of proper locking when performing operations on a file, leading to a race condition. Affected versions include Apex One 2019 (On-prem) and Apex One as a Service versions before the April 2023 Maintenance release [1][2].

Exploitation

To exploit this vulnerability, an attacker must first obtain the ability to execute low-privileged code on the target system. The attacker then triggers a race condition by manipulating file operations in the Apex One Client Plug-in Service Manager, taking advantage of the missing synchronization [2].

Impact

Successful exploitation allows a local attacker to escalate privileges to SYSTEM, enabling arbitrary code execution with the highest level of system access. This can lead to full compromise of the affected endpoint [2].

Mitigation

Trend Micro has released fixes: for Apex One (On-prem), apply SP1 Critical Patch B12024; for Apex One as a Service, update to the April 2023 Maintenance (Build 202304, Security Agent version 14.0.12105) [1]. No workarounds are documented; applying the latest patches is strongly recommended.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.