Security News Trend Micro, Tanium, ESET and Tenable Patch Severe Product Vulnerabilities

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,070
5,681
2,168
Germany
The cybersecurity companies patched critical and high-severity vulnerabilities in some of their products.
Firewalls and other cybersecurity products
Cybersecurity companies TrendAI (Trend Micro), ESET, Tenable, and Tanium released product updates this month to patch severe vulnerabilities.

Tenable told customers this week that it has fixed a critical-severity path traversal in the Tenable Agent. The security hole, tracked as CVE-2026-15265, may allow an attacker to achieve remote code execution.
ESET informed customers on Tuesday that it has discovered and patched a high-severity local privilege escalation vulnerability in Inspect Connector for Windows.

“On systems with the affected ESET product installed, an attacker could send self-crafted Advanced Local Procedure Call (ALPC) requests to the vulnerable process’ interface,” ESET explained in its advisory. “Without proper authentication or origin validation in place, this message would be accepted and processed, enabling the attacker to access restricted functionality.”
ESET has also published a separate advisory for a medium-severity DoS vulnerability in its security products for Linux.
Firewalls and other cybersecurity products
Cybersecurity companies TrendAI (Trend Micro), ESET, Tenable, and Tanium released product updates this month to patch severe vulnerabilities.

Tenable told customers this week that it has fixed a critical-severity path traversal in the Tenable Agent. The security hole, tracked as CVE-2026-15265, may allow an attacker to achieve remote code execution.
ESET informed customers on Tuesday that it has discovered and patched a high-severity local privilege escalation vulnerability in Inspect Connector for Windows.

“On systems with the affected ESET product installed, an attacker could send self-crafted Advanced Local Procedure Call (ALPC) requests to the vulnerable process’ interface,” ESET explained in its advisory. “Without proper authentication or origin validation in place, this message would be accepted and processed, enabling the attacker to access restricted functionality.”
ESET has also published a separate advisory for a medium-severity DoS vulnerability in its security products for Linux.

Tanium informed customers last week about a high-severity DoS flaw affecting Tanium Server.
“This vulnerability could allow an unauthenticated, network-based attacker to perform a denial of service attack against the Tanium Server,” the company noted.
Trend Micro informed Cleaner One Pro users last week of a medium-severity arbitrary file deletion vulnerability that could “allow a malicious app already running on your device to trick the cleanup process into deleting a file it shouldn’t have access to.”
The vendor noted that local access is required for exploitation and the vulnerability cannot be exploited remotely.
Palo Alto Networks also released patches this month, addressing over a dozen vulnerabilities in its products.
While there is no evidence of exploitation for the latest vulnerabilities, it’s not uncommon for threat actors to target security products in their attacks. For instance, Palo Alto Networks and Trend Micro recently confirmed in-the-wild exploitation.
 
First time I've heard about this, but since ESET patched it... fine.

I agree. How many people would this have affected in the first place (could send)? Nothing is 100%. Some more "scareware" for our daily lives 😐
“On systems with the affected ESET product installed, an attacker could send self-crafted Advanced Local Procedure Call (ALPC) requests to the vulnerable process’ interface,” ESET explained in its advisory. “Without proper authentication or origin validation in place, this message would be accepted and processed, enabling the attacker to access restricted functionality.”
 
Last edited:
I agree. How many people would this have affected in the first place (could send)? Nothing is 100%. Some more "scareware" for our daily lives 😐
I am not sure if this is related, but I have seen a couple of vids on an Arab security forum. The member could disable Eset, Avast and Norton by running his malicious sample. He concluded that the only way to protect the product from being disabled is by protection its settings with a password.

Unfortunately they're no longer accepting new members, so I could not ask for more details.
 
I am not sure if this is related, but I have seen a couple of vids on an Arab security forum. The member could disable Eset, Avast and Norton by running his malicious sample. He concluded that the only way to protect the product from being disabled is by protection its settings with a password.

Unfortunately they're no longer accepting new members, so I could not ask for more details.
I've heard of that before, I just don't remember what AV that was mentioned about, unless it was the ones you mentioned? I do remember someone asking if the F-Secure protection could be disabled even though it has tamper protection. I don't remember what I did, but I wasn't able to totally disable its protection when I ran my simple test. I'm sure someone who knew more of what they were doing and how, may have tested it better than I had? Their settings also need to have Admin privileges to make any changes to them.

Screenshot 2026-07-19 111655.png
 
Basically if software is not updated promptly, you are left at risk.

This makes a person look at alternatives, like Voodooshiel plus DefenderUI plus possibly (optional) Fort Firewall. Which would pretty much secure your PC even if they were never updated again.
But, there's still the possible issue of, with people, clicking, ticking and allowing on their devices?
 
I've heard of that before, I just don't remember what AV that was mentioned about, unless it was the ones you mentioned? I do remember someone asking if the F-Secure protection could be disabled even though it has tamper protection. I don't remember what I did, but I wasn't able to totally disable its protection when I ran my simple test. I'm sure someone who knew more of what they were doing and how, may have tested it better than I had? Their settings also need to have Admin privileges to make any changes to them.

View attachment 298914
F-Secure did not have tamper protection a few years ago. They recently added it.

You reminded me of sth very important. If you're using SUA, the chances of disabling the protection of ur security solution are much lower. But we always should password-protect the settings.

Doing some research it seems the patched vulnerabilities have nothing to do with disabling the protection of the mentioned products.
 
  • Like
Reactions: Jonny Quest
Basically if software is not updated promptly, you are left at risk.

This makes a person look at alternatives, like Voodooshiel plus DefenderUI plus possibly (optional) Fort Firewall. Which would pretty much secure your PC even if they were never updated again.
By using many products, you increase the attack surface.
 
He concluded that the only way to protect the product from being disabled is by protection its settings with a password.
Not fool proof, I remember when I ran Kaspersky IS, set a password and bam password was changed to something else and I couldn't reset or change settings.

I had to do a fresh install, wasn't as bad as Bitdefender deleting Windows Firewall but it was close.
 
  • HaHa
Reactions: Divine_Barakah
Not fool proof, I remember when I ran Kaspersky IS, set a password and bam password was changed to something else and I couldn't reset or change settings.

I had to do a fresh install, wasn't as bad as Bitdefender deleting Windows Firewall but it was close.
We should make a documentary about your experience with those products