Insecure DLL loading in VPN Proxy One Pro - CVE-2026-67212
Published: July 30, 2026 / Updated: July 30, 2026
Vulnerability details
The vulnerability allows a local user to escalate privileges.
The vulnerability exists due to an uncontrolled search path element in a Trend Micro VPN process when loading a specific module. A local user can cause a specific module to be loaded into a process running with SYSTEM privileges to escalate privileges.
Exploitation is possible only under special circumstances.