CVE-2024-55955
31.12.2024, 17:15
An incorrect permissions assignment vulnerability in Trend Micro Deep Security 20.0 agents between versions 20.0.1-9400 and 20.0.1-23340 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.Enginsight
Vendor | Product | Version |
---|---|---|
trendmicro | deep_security_agent | 20.0.1:update12510 |
trendmicro | deep_security_agent | 20.0.1:update14610 |
trendmicro | deep_security_agent | 20.0.1:update17380 |
trendmicro | deep_security_agent | 20.0.1:update19250 |
trendmicro | deep_security_agent | 20.0.1:update21510 |
trendmicro | deep_security_agent | 20.0.1:update9400 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-427 - Uncontrolled Search Path ElementThe product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
- CWE-732 - Incorrect Permission Assignment for Critical ResourceThe product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.