Vulnerability Description
A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges and execute arbitrary code on an affected machine. In certain circumstances, attackers that have legitimate access to the domain may be able to remotely inject commands to other machines in the same domain. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability locally and must have domain user privileges to affect other machines.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Trendmicro | Deep Security Agent | 20.0 |
Related Weaknesses (CWE)
References
- https://success.trendmicro.com/en-US/solution/KA-0018154Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-24-1516/Third Party Advisory
FAQ
What is CVE-2024-51503?
CVE-2024-51503 is a vulnerability with a CVSS score of 8.0 (HIGH). A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges and execute arbitrary code on an affected machine....
How severe is CVE-2024-51503?
CVE-2024-51503 has been rated HIGH with a CVSS base score of 8.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2024-51503?
Check the references section above for vendor advisories and patch information. Affected products include: Trendmicro Deep Security Agent.