SB2025092503 - Privilege escalation in Trend Micro Antivirus for Mac
Published: September 25, 2025
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 security vulnerability.
1) Improper Enforcement of Behavioral Workflow (CVE-ID: CVE-2025-59931)
The vulnerability allows a local user to escalate privileges on the system.
The vulnerability exists due to incorrect deletion process when uninstalling the application by deleting it from the Applications. Information about the application is left behind in a specific LaunchDaemon directory. A local user can place a malicious executable at the expected path and execute it as root after system restart, leading to privilege escalation.
Remediation
Install update from vendor's website.