Cyber Posture

CVE-2024-58104

High

Published: 25 March 2025

Published
25 March 2025
Modified
01 August 2025
KEV Added
Patch
CVSS Score 7.3 CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
EPSS Score 0.0001 1.3th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Description

Adversaries may exploit vulnerabilities to evade detection by hiding activity, suppressing logging, or operating within trusted or unmonitored components.

Security Summary

CVE-2024-58104 is a vulnerability in the Trend Micro Apex One Security Agent Plug-in User Interface Manager that could allow a local attacker to bypass existing security controls and execute arbitrary code on affected installations. Published on 2025-03-25, it carries a CVSS v3.1 base score of 7.3 (AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H) and maps to CWE-269 (Improper Privilege Management).

Exploitation requires an attacker to first obtain the ability to execute low-privileged code on the target system, along with local access, low privileges, and user interaction. Successful exploitation enables arbitrary code execution, resulting in high impacts to confidentiality, integrity, and availability.

Trend Micro has published mitigation guidance in their advisory at https://success.trendmicro.com/en-US/solution/KA-0018217.

Details

CWE(s)
CWE-269

Affected Products

trendmicro
apex one
≤ 14.0.14203 · ≤ 2019.13140

MITRE ATT&CK Enterprise Techniques

T1068 Exploitation for Privilege Escalation Privilege Escalation
Adversaries may exploit software vulnerabilities in an attempt to elevate privileges.
T1211 Exploitation for Stealth Stealth
Adversaries may exploit vulnerabilities to evade detection by hiding activity, suppressing logging, or operating within trusted or unmonitored components.
Why these techniques?

Local vulnerability enabling bypass of security controls and arbitrary code execution due to improper privilege management directly maps to exploitation for privilege escalation (T1068) and defense evasion (T1211).

Confidence: HIGH · MITRE ATT&CK Enterprise v19.0

References