Cyber Resilience

CVE-2024-36304

Race Condition in Trendmicro Apex One ≤ 14.0.13139

Published
10 June 2024
Modified
16 June 2025
CVSS Score v3.1 7.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score 0.0040 33th percentile
Risk Priority 55 floored blend · peak EPSS

Summary

CVE-2024-36304 is a high-severity Time-of-check Time-of-use (TOCTOU) Race Condition (CWE-367) vulnerability in Trendmicro Apex One. Its CVSS base score is 7.8 (High).

Operationally, ranked at the 33th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability Data

A Time-of-Check Time-Of-Use vulnerability in the Trend Micro Apex One and Apex One as a Service agent could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged…

more

code on the target system in order to exploit this vulnerability.

CWE(s)

Related Threats

CVEs Like This One

CVE-2025-71215Same product: Trendmicro Apex One
CVE-2025-71216Same product: Trendmicro Apex One
CVE-2026-45208Same product: Trendmicro Apex One
CVE-2023-52094Same product: Trendmicro Apex One
CVE-2023-47200Same product: Trendmicro Apex One
CVE-2024-55917Same product: Trendmicro Apex One
CVE-2023-47199Same product: Trendmicro Apex One
CVE-2024-58104Same product: Trendmicro Apex One
CVE-2025-49158Same product: Trendmicro Apex One
CVE-2023-52093Same product: Trendmicro Apex One

Affected Assets

trendmicro
apex one
≤ 14.0.13139 · 14.0 — 14.0.0.12980

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)

Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)
  • V15.4.2
  • V17.2.6

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-367

Timestamps meeting UTC or offset standards help identify TOCTOU issues through precise chronological reconstruction of check/use operations.

Mitigating Controls (NIST CSF 2.0) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→CSF cross-walk (authority under review) — links open the control.

PR.PS-06 mostly match
prevents

Secure SDLC practices directly include coding standards and reviews that prevent TOCTOU race conditions.

Mitigating Controls (ISO/IEC 27001:2022 Annex A) AI

Derived directly from the weakness types (CWEs) cited in the NVD entry via our AI-authored CWE→ISO cross-walk (authority under review) — links open the control.

none

Reliable, synchronized time across systems narrows the exploitable window in which a resource state can change between a security check and its use.

References