Views:

Release Date: July 22, 2026

CVE Identifier: CVE-2026-67212

Platform(s): Microsoft Windows

CVSS v3.1 Score: 7.0 (AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H)

Severity Rating: High


Summary

Trend Micro published version 6.0.1036 of Trend Micro VPN on July 22, 2026, which addresses a vulnerability that could allow local privilege escalation under special circumstances due to an uncontrolled search path element.


Affected Version(s)

Product Affected Version(s) Platform Language(s)
Trend Micro VPN 6.0.1028 and below Windows English

Solution

Trend Micro has released an update that resolves the issue.

Product Updated Version(s) Platform Language(s)
Trend Micro VPN 6.0.1036 Windows English

For step-by-step instructions on updating your app, see How to Upgrade Trend Micro VPN App to the Latest Version.


Vulnerability Details

Trend Micro VPN, version 6.0.1028 and below, is vulnerable to a local privilege escalation issue related to an uncontrolled search path element. A low-privileged local user who exploits the vulnerability could cause a specific module to be loaded into a Trend Micro VPN process running with SYSTEM privileges, resulting in local privilege escalation.

Trend Micro has received no reports nor is aware of any actual attacks against the affected product related to this vulnerability at this time.


Mitigating Factors

None identified. Customers are advised to ensure they always have the latest version of the program.


Acknowledgement

Trend Micro would like to thank Xavier DANEST working with Trend Micro's Zero Day Initiative (ZDI) for responsibly disclosing this issue and working with Trend Micro to help protect our customers.


External Reference

  • ZDI-CAN-29830

Additional Assistance

Customers who have questions are encouraged to contact Trend Micro Technical Support for further assistance.

Add a comment