VYPR
Unrated severityNVD Advisory· Published Jun 26, 2023· Updated Dec 5, 2024

CVE-2023-34144

CVE-2023-34144

Description

An untrusted search path vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate their privileges on affected installations.

Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

This is a similar, but not identical vulnerability as CVE-2023-34145.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An untrusted search path vulnerability in Trend Micro Apex One security agent allows local attackers to escalate privileges to SYSTEM.

Vulnerability

An untrusted search path vulnerability exists in the Trend Micro Apex One and Apex One as a Service security agent, specifically within the Apex One Client Plug-in Service Manager. The issue arises when the service loads a module from an untrusted location, allowing an attacker to control the loaded module. Affected versions include Apex One 2019 (On-prem) and Apex One as a Service versions before the May 2023 Maintenance [1][2].

Exploitation

To exploit this vulnerability, an attacker must first obtain the ability to execute low-privileged code on the target system. Once achieved, the attacker can leverage the untrusted search path by placing a malicious module in a location that the service will load, thereby triggering the vulnerability [1].

Impact

Successful exploitation allows the attacker to escalate privileges and execute arbitrary code in the context of the SYSTEM account, leading to full compromise of the affected system [1].

Mitigation

Trend Micro has released updates to address this vulnerability: for Apex One (On-prem), apply Service Pack 1 Critical Patch B12033; for Apex One as a Service, apply the May 2023 Maintenance (Hotfix Build 202305, Security Agent version 14.0.12518) [2]. No workarounds have been provided.

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.