Critical Arbitrary File Deletion in Trend Micro Cleaner One Pro (CVE‑2026‑62660) Threatens Endpoint Integrity
What It Is — Trend Micro’s Cleaner One Pro contains a flaw in its “Junk Files Cleanup” routine that lets a low‑privileged attacker create a junction point and force the service, which runs as SYSTEM, to delete arbitrary files.
Exploitability — Local‑only; an attacker must already have the ability to run low‑privileged code. No public exploit code has been released, but the vulnerability is fully disclosed and patched. CVSS 5.6 (AV:L/AC:L/PR:L/UI:R/S:U/C:N/I:L/A:H).
Affected Products — Trend Micro Cleaner One Pro (all versions prior to the July 2026 security update).
Why It Matters for Compliance & Audit Readiness
- SOC 2 CC6.1 (Vulnerability Management) requires documented evidence that known software flaws are remediated promptly; a local file‑deletion bug can be a control‑gap indicator during an audit.
- Continuous control monitoring must capture patch‑deployment status for endpoint tools; missing evidence can trigger “control not operating effectively” findings.
- Enterprise buyers increasingly demand proof (e.g., audit‑ready logs) that endpoint‑security products are kept up‑to‑date, especially when the product runs with SYSTEM privileges.
Recommended Actions
- Deploy Trend Micro’s July 2026 update (TMKA‑13319) across all managed endpoints.
- Map the vulnerability to SOC 2 CC6.1 and CC7.2 (Change Management) controls; record patch‑installation timestamps in your configuration‑management database (CMDB).
- Enable continuous monitoring of endpoint‑security agent versions and generate audit‑ready reports that show compliance with the patch schedule.
- Conduct a post‑patch validation scan to confirm the junction‑creation path is no longer exploitable.