← Back

CVE-2024-51503

nvd nist
Published: Nov 19, 2024Modified: Jun 17, 2026

JSON object

Loading...
8.8
Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Exploitability: 2.8 / Impact: 5.9
Source: NVD

Description

A security agent manual scan command injection vulnerability in the Trend Micro Deep Security 20 Agent could allow an attacker to escalate privileges and execute arbitrary code on an affected machine. In certain circumstances, attackers that have legitimate access to the domain may be able to remotely inject commands to other machines in the same domain. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability locally and must have domain user privileges to affect other machines.

Affected (64)

1 product
Deep Security Agent
Configuration A
64 vulnerable
Vulnerable SoftwareAffected Versions
Trendmicro
Version 20.0.1
Version 20.0.1 update12510
Version 20.0.1 update14610
Version 20.0.1 update17380
Version 20.0.1 update19250
Version 20.0.1 update3180
Version 20.0.1 update4540
Version 20.0.1 update690
Version 20.0.1 update7380
Version 20.0.1 update9400
Version 20.0
Version 20.0 update1337
Version 20.0 update1559
Version 20.0 update158
Version 20.0 update167
Version 20.0 update1681
Version 20.0 update173
Version 20.0 update180
Version 20.0 update1822
Version 20.0 update182
Version 20.0 update183
Version 20.0 update1876
Version 20.0 update190
Version 20.0 update198
Version 20.0 update2009
Version 20.0 update208
Version 20.0 update213
Version 20.0 update2204
Version 20.0 update223
Version 20.0 update224
Version 20.0 update2395
Version 20.0 update2419
Version 20.0 update2593
Version 20.0 update2740
Version 20.0 update2921
Version 20.0 update3165
Version 20.0 update3288
Version 20.0 update3445
Version 20.0 update3530
Version 20.0 update3771
Version 20.0 update3964
Version 20.0 update4185
Version 20.0 update4416
Version 20.0 update4726
Version 20.0 update4959
Version 20.0 update5137
Version 20.0 update5394
Version 20.0 update5512
Version 20.0 update5761
Version 20.0 update5810
Version 20.0 update5995
Version 20.0 update6313
Version 20.0 update6690
Version 20.0 update6860
Version 20.0 update690
Version 20.0 update7119
Version 20.0 update7303
Version 20.0 update7476
Version 20.0 update7719
Version 20.0 update7943
Version 20.0 update8137
Version 20.0 update8268
Version 20.0 update8438
Version 20.0 update877

References (2)

Source: security@trendmicro.com
Vendor Advisory
Source: security@trendmicro.com
Third Party Advisory

Timeline

No history available yet.