An incorrect permissions assignment vulnerability in Trend Micro Deep Security 20.0 agents between versions 20.0.1-9400 and 20.0.1-23340 could allow a local attacker to escalate privileges on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://success.trendmicro.com/en-US/solution/KA-0018571 |
History
Tue, 31 Dec 2024 18:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 31 Dec 2024 16:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | An incorrect permissions assignment vulnerability in Trend Micro Deep Security 20.0 agents between versions 20.0.1-9400 and 20.0.1-23340 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
First Time appeared |
Trendmicro
Trendmicro deep Security Agent |
|
Weaknesses | CWE-427 | |
CPEs | cpe:2.3:a:trendmicro:deep_security_agent:20.0:update10940:*:*:long_term_support:*:*:* | |
Vendors & Products |
Trendmicro
Trendmicro deep Security Agent |
|
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: trendmicro
Published: 2024-12-31T16:19:35.471Z
Updated: 2024-12-31T17:24:18.855Z
Reserved: 2024-12-13T18:38:39.678Z
Link: CVE-2024-55955
Vulnrichment
Updated: 2024-12-31T17:24:15.438Z
NVD
Status : Received
Published: 2024-12-31T17:15:09.270
Modified: 2024-12-31T17:15:09.270
Link: CVE-2024-55955
Redhat
No data.