PT-2024-36618 · Trend Micro · Trend Micro Deep Security Agent

CVE-2024-55955

·

Published

2024-12-19

·

Updated

2025-09-09

CVSS v3.1

7.3

High

VectorAV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Trend Micro Deep Security Agent versions 20.0.1-9400 through 20.0.1-23340
Description An incorrect permissions assignment issue could allow a local attacker to escalate privileges on affected installations. To exploit this issue, an attacker must first obtain the ability to execute low-privileged code on the target system.
Recommendations For versions 20.0.1-9400 through 20.0.1-23340, update to a version outside of this range to resolve the issue. As a temporary workaround, consider restricting access to sensitive areas of the system to minimize the risk of exploitation.

Fix

Incorrect Permission

Uncontrolled Search Path Element

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-55955
ZDI-25-008

Affected Products

Trend Micro Deep Security Agent