CVE-2024-48903
Trend Micro Deep Security Improper Access Control Local Privilege Escalation Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
An improper access control vulnerability in Trend Micro Deep Security Agent 20 could allow a local attacker to escalate privileges on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
This vulnerability allows local attackers to escalate privileges on affected installations of Trend Micro Deep Security. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The specific flaw exists within the Anti-Malware Solution Platform. The issues results from insufficient access control on a sensitive folder. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of SYSTEM.
CVSS Scores
SSVC
- Decision:Track*
Timeline
- 2024-10-09 CVE Reserved
- 2024-10-17 CVE Published
- 2024-10-22 CVE Updated
- 2024-10-23 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://success.trendmicro.com/en-US/solution/KA-0017997 | ||
https://www.zerodayinitiative.com/advisories/ZDI-24-1419 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Trend Micro, Inc. Search vendor "Trend Micro, Inc." | Trend Micro Deep Security Agent Search vendor "Trend Micro, Inc." for product "Trend Micro Deep Security Agent" | >= 20.0.0 < 20.0.1-17380 Search vendor "Trend Micro, Inc." for product "Trend Micro Deep Security Agent" and version " >= 20.0.0 < 20.0.1-17380" | en |
Affected
|