Improper Access Control Vulnerability in Trend Micro Deep Security Agent 20 Could Lead to Escalated Privileges
CVE-2024-48903

7.8HIGH

Key Information:

Vendor
CVE Published:
22 October 2024

Summary

An improper access control vulnerability exists in the Trend Micro Deep Security Agent 20. This issue can be exploited by local attackers to escalate privileges on systems where the software is installed. To successfully execute the exploit, an attacker must first have the ability to run low-privileged code on the affected system. The vulnerability highlights the importance of robust access controls to safeguard against unauthorized privilege escalation and potential security breaches.

Affected Version(s)

Trend Micro Deep Security Agent 20 < 20.0.1-17380

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

.