CVE-2024-55955
CVE-2024-55955 is a privilege escalation vulnerability affecting Trend Micro Deep Security 20.0. This flaw allows a local attacker to gain higher-level access on systems running vulnerable agent versions between 20.0.1-9400 and 20.0.1-23340. Although the CVSS score is 6.7, indicating a medium severity, the SOCRadar Vulnerability Risk Score (SVRS) of 30 suggests a lower immediate risk compared to critical vulnerabilities. To exploit this, an attacker needs existing low-level code execution capabilities on the target machine. If successful, this vulnerability enables an attacker to perform unauthorized actions with elevated privileges. The incorrect permissions assignment is located within Trend Micro Deep Security Agents. Organizations using affected versions should apply the available security update promptly to mitigate the risk of unauthorized access and potential system compromise.
Indicators of Compromise
Exploits
News
Social Media
Affected Software
References
CWE Details
CVE Radar
Real-time CVE Intelligence & Vulnerability Management Platform
CVE Radar provides comprehensive vulnerability intelligence by monitoring CVE databases, security advisories, and threat feeds. Get instant updates on new vulnerabilities, exploit details, and mitigation strategies specific to your assets.