CVE-2025-53503

7.8 HIGH

📋 TL;DR

Trend Micro Cleaner One Pro contains a privilege escalation vulnerability that allows local attackers to delete privileged Trend Micro files, including the software's own files. This could disrupt security functionality and potentially allow further system compromise. Only users of Trend Micro Cleaner One Pro are affected.

💻 Affected Systems

Products:
  • Trend Micro Cleaner One Pro
Versions: Versions prior to 6.6.0.2106
Operating Systems: Windows
Default Config Vulnerable: ⚠️ Yes
Notes: Only affects Trend Micro Cleaner One Pro, not other Trend Micro products. Requires local access to the system.

📦 What is this software?

⚠️ Risk & Real-World Impact

🔴

Worst Case

An attacker could delete critical Trend Micro files, disabling security protections and potentially enabling full system compromise through follow-on attacks.

🟠

Likely Case

Local attackers could delete Trend Micro files, causing software malfunction and potentially creating opportunities for privilege escalation or persistence.

🟢

If Mitigated

With proper access controls and monitoring, impact would be limited to potential service disruption of Trend Micro software.

🌐 Internet-Facing: LOW - This is a local privilege escalation requiring local access to the system.
🏢 Internal Only: MEDIUM - Internal attackers with local access could exploit this to disrupt security software and potentially escalate privileges.

🎯 Exploit Status

Public PoC: ✅ No
Weaponized: UNKNOWN
Unauthenticated Exploit: ✅ No
Complexity: LOW

Exploitation requires local access to the system. No public exploit code has been identified at this time.

🛠️ Fix & Mitigation

✅ Official Fix

Patch Version: 6.6.0.2106

Vendor Advisory: https://helpcenter.trendmicro.com/en-us/article/tmka-12951

Restart Required: Yes

Instructions:

1. Open Trend Micro Cleaner One Pro. 2. Navigate to Settings or Help menu. 3. Check for updates and install version 6.6.0.2106 or later. 4. Restart the computer after installation completes.

🔧 Temporary Workarounds

Restrict Local Access

windows

Limit local access to systems running Trend Micro Cleaner One Pro to trusted users only.

Monitor File Deletion Events

windows

Enable auditing for file deletion events in Trend Micro directories.

auditpol /set /subcategory:"File System" /success:enable /failure:enable

🧯 If You Can't Patch

  • Uninstall Trend Micro Cleaner One Pro if not essential for operations
  • Implement strict access controls to limit local user privileges on affected systems

🔍 How to Verify

Check if Vulnerable:

Check Trend Micro Cleaner One Pro version in the application's About or Settings section. If version is below 6.6.0.2106, the system is vulnerable.

Check Version:

Check application version through GUI: Settings → About or Help → About

Verify Fix Applied:

Confirm Trend Micro Cleaner One Pro version is 6.6.0.2106 or higher in the application's About or Settings section.

📡 Detection & Monitoring

Log Indicators:

  • Unexpected file deletion events in Trend Micro program directories
  • Failed attempts to access Trend Micro protected files

Network Indicators:

  • No network indicators - this is a local privilege escalation

SIEM Query:

EventID=4663 AND ObjectName LIKE "%Trend Micro%" AND AccessMask=0x10000

🔗 References

📤 Share & Export