PT-2024-36618 · Trend Micro · Trend Micro Deep Security Agent
Published
2024-12-19
·
Updated
2025-09-09
·
CVE-2024-55955
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Trend Micro Deep Security Agent versions 20.0.1-9400 through 20.0.1-23340
Description
An incorrect permissions assignment issue could allow a local attacker to escalate privileges on affected installations. To exploit this issue, an attacker must first obtain the ability to execute low-privileged code on the target system.
Recommendations
For versions 20.0.1-9400 through 20.0.1-23340, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the system to minimize the risk of exploitation.
Fix
Incorrect Permission
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trend Micro Deep Security Agent