An incorrect permissions assignment vulnerability in Trend Micro Deep Security 20.0 agents between versions 20.0.1-9400 and 20.0.1-23340 could allow a local attacker to escalate privileges on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Metrics
Affected Vendors & Products
References
| Link | Providers |
|---|---|
| https://success.trendmicro.com/en-US/solution/KA-0018571 |
|
History
Tue, 09 Sep 2025 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Microsoft
Microsoft windows |
|
| Weaknesses | CWE-732 | |
| CPEs | cpe:2.3:a:trendmicro:deep_security_agent:20.0.1:update12510:*:*:long_term_support:*:*:* cpe:2.3:a:trendmicro:deep_security_agent:20.0.1:update14610:*:*:long_term_support:*:*:* cpe:2.3:a:trendmicro:deep_security_agent:20.0.1:update17380:*:*:long_term_support:*:*:* cpe:2.3:a:trendmicro:deep_security_agent:20.0.1:update19250:*:*:long_term_support:*:*:* cpe:2.3:a:trendmicro:deep_security_agent:20.0.1:update21510:*:*:long_term_support:*:*:* cpe:2.3:a:trendmicro:deep_security_agent:20.0.1:update9400:*:*:long_term_support:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* |
|
| Vendors & Products |
Microsoft
Microsoft windows |
Tue, 31 Dec 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 31 Dec 2024 16:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An incorrect permissions assignment vulnerability in Trend Micro Deep Security 20.0 agents between versions 20.0.1-9400 and 20.0.1-23340 could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| First Time appeared |
Trendmicro
Trendmicro deep Security Agent |
|
| Weaknesses | CWE-427 | |
| CPEs | cpe:2.3:a:trendmicro:deep_security_agent:20.0:update10940:*:*:long_term_support:*:*:* | |
| Vendors & Products |
Trendmicro
Trendmicro deep Security Agent |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: trendmicro
Published: 2024-12-31T16:19:35.471Z
Updated: 2025-03-05T04:55:27.005Z
Reserved: 2024-12-13T18:38:39.678Z
Link: CVE-2024-55955
Updated: 2024-12-31T17:24:15.438Z
Status : Analyzed
Published: 2024-12-31T17:15:09.270
Modified: 2025-09-09T14:45:36.713
Link: CVE-2024-55955
No data.