CVE-2023-32556
Description
A link following vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to disclose sensitive information.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A link following vulnerability in Trend Micro Apex One agent allows local attackers to disclose sensitive information as SYSTEM via a mount point.
Vulnerability
CVE-2023-32556 is a link following vulnerability in the Trend Micro Apex One Security Agent, specifically within the NT Apex One RealTime Scan Service. By creating a mount point, a local attacker can abuse the service to disclose the contents of a file. The vulnerability affects Apex One 2019 (On-prem) and Apex One as a Service versions before the April 2023 Maintenance build [1][2].
Exploitation
An attacker must first obtain the ability to execute low-privileged code on the target system. The specific flaw exists within the NT Apex One RealTime Scan Service, and exploitation involves creating a mount point to trick the service into reading a file of the attacker's choice [2].
Impact
Successful exploitation allows an attacker to disclose sensitive information, potentially including system files, in the context of the SYSTEM account. This can lead to information disclosure with high confidentiality impact [2].
Mitigation
Trend Micro has released fixes: for Apex One (On-prem), apply Critical Patch B12024; for Apex One as a Service, apply the April 2023 Maintenance (Build 202304). Customers are encouraged to obtain the latest versions [1].
AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
3- Trend Micro, Inc./Trend Micro Apex Onev5Range: 2019
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2News mentions
0No linked articles in our index yet.