PT-2024-8684 · Trend Micro · Trend Micro Deep Security Agent
Simon Zuckerbraun
·
Published
2024-11-18
·
Updated
2025-09-04
·
CVE-2024-51503
CVSS v3.1
8.8
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Trend Micro Deep Security Agent version 20
Description
A security agent manual scan command injection issue in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges and execute arbitrary code on an affected machine. In certain circumstances, attackers with legitimate access to the domain may be able to remotely inject commands to other machines in the same domain. An attacker must first obtain the ability to execute low-privileged code on the target system to exploit this issue locally and must have domain user privileges to affect other machines.
Recommendations
For Trend Micro Deep Security Agent version 20, update to a version that includes the fix for this issue to prevent command injection and remote code execution. As a temporary workaround, consider restricting access to the manual scan feature until a patch is available. Additionally, ensure that domain user privileges are properly managed to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Trend Micro Deep Security Agent