VYPR
Unrated severityNVD Advisory· Published Jun 26, 2023· Updated Dec 4, 2024

CVE-2023-34147

CVE-2023-34147

Description

An exposed dangerous function vulnerability in the Trend Micro Apex One and Apex One as a Service security agent could allow a local attacker to escalate privileges and write an arbitrary value to specific Trend Micro agent subkeys on affected installations.

Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

This is a similar, but not identical vulnerability as CVE-2023-34146 and CVE-2023-34148.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A local attacker can leverage an exposed dangerous function in Trend Micro Apex One's NT Listener service to escalate privileges to SYSTEM and execute arbitrary code.

Vulnerability

An exposed dangerous function vulnerability exists in the Trend Micro Apex One and Apex One as a Service security agent, specifically within the Apex One NT Listener service. This flaw allows a local attacker to write an arbitrary value to specific Trend Micro agent subkeys. Affected versions include Apex One 2019 (On-prem) and Apex One as a Service prior to the May 2023 Maintenance build (Security Agent version 14.0.12518). The vulnerability is similar but not identical to CVE-2023-34146 and CVE-2023-34148 [1][2].

Exploitation

An attacker must first obtain the ability to execute low-privileged code on the target system. The specific flaw arises from an exposed dangerous function in the Apex One NT Listener service. By leveraging this function, the attacker can write an arbitrary value to specific Trend Micro agent subkeys, which can then be used to escalate privileges [1].

Impact

Successful exploitation allows the attacker to escalate privileges and execute arbitrary code in the context of SYSTEM, granting full control over the affected system with high impact on confidentiality, integrity, and availability [1].

Mitigation

Trend Micro has released fixes for both affected products: for Apex One 2019 (On-prem), apply SP1 CP B12033; for Apex One as a Service, apply the May 2023 Maintenance hotfix (Build 202305, Security Agent version 14.0.12518). Customers are encouraged to obtain the latest product version [2].

AI Insight generated on May 25, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

3

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.