PT-2024-5116 · Trend Micro · Trend Micro Deep Security
Published
2024-01-03
·
Updated
2025-03-13
·
CVE-2024-36358
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Trend Micro Deep Security versions 20.x below 20.0.1-3180
Description:
A link following issue in Trend Micro Deep Security could allow a local attacker to escalate privileges on affected installations. The vulnerability is related to incorrect link resolution before accessing a file, which may enable an attacker to execute arbitrary code. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this issue.
Recommendations:
For versions 20.x below 20.0.1-3180, update to a version above 20.0.1-3180 to resolve the issue.
At the moment, there is no information about additional mitigation measures for this specific issue.
Fix
Link Following
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trend Micro Deep Security