A link following vulnerability in the Trend Micro Deep Security 20.0 and Trend Micro Cloud One - Endpoint and Workload Security Agent could allow a local attacker to escalate privileges on affected installations.
Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Deep_security | Trendmicro | 20.0 (including) | 20.0 (including) |
Deep_security_agent | Trendmicro | 20.0-update1337 (including) | 20.0-update1337 (including) |
Deep_security_agent | Trendmicro | 20.0-update1559 (including) | 20.0-update1559 (including) |
Deep_security_agent | Trendmicro | 20.0-update158 (including) | 20.0-update158 (including) |
Deep_security_agent | Trendmicro | 20.0-update167 (including) | 20.0-update167 (including) |
Deep_security_agent | Trendmicro | 20.0-update1681 (including) | 20.0-update1681 (including) |
Deep_security_agent | Trendmicro | 20.0-update173 (including) | 20.0-update173 (including) |
Deep_security_agent | Trendmicro | 20.0-update180 (including) | 20.0-update180 (including) |
Deep_security_agent | Trendmicro | 20.0-update182 (including) | 20.0-update182 (including) |
Deep_security_agent | Trendmicro | 20.0-update1822 (including) | 20.0-update1822 (including) |
Deep_security_agent | Trendmicro | 20.0-update183 (including) | 20.0-update183 (including) |
Deep_security_agent | Trendmicro | 20.0-update1876 (including) | 20.0-update1876 (including) |
Deep_security_agent | Trendmicro | 20.0-update190 (including) | 20.0-update190 (including) |
Deep_security_agent | Trendmicro | 20.0-update198 (including) | 20.0-update198 (including) |
Deep_security_agent | Trendmicro | 20.0-update2009 (including) | 20.0-update2009 (including) |
Deep_security_agent | Trendmicro | 20.0-update208 (including) | 20.0-update208 (including) |
Deep_security_agent | Trendmicro | 20.0-update213 (including) | 20.0-update213 (including) |
Deep_security_agent | Trendmicro | 20.0-update2204 (including) | 20.0-update2204 (including) |
Deep_security_agent | Trendmicro | 20.0-update223 (including) | 20.0-update223 (including) |
Deep_security_agent | Trendmicro | 20.0-update224 (including) | 20.0-update224 (including) |
Deep_security_agent | Trendmicro | 20.0-update2419 (including) | 20.0-update2419 (including) |
Deep_security_agent | Trendmicro | 20.0-update2593 (including) | 20.0-update2593 (including) |
Deep_security_agent | Trendmicro | 20.0-update2740 (including) | 20.0-update2740 (including) |
Deep_security_agent | Trendmicro | 20.0-update2921 (including) | 20.0-update2921 (including) |
Deep_security_agent | Trendmicro | 20.0-update3165 (including) | 20.0-update3165 (including) |
Deep_security_agent | Trendmicro | 20.0-update3288 (including) | 20.0-update3288 (including) |
Deep_security_agent | Trendmicro | 20.0-update3445 (including) | 20.0-update3445 (including) |
Deep_security_agent | Trendmicro | 20.0-update3530 (including) | 20.0-update3530 (including) |
Deep_security_agent | Trendmicro | 20.0-update3771 (including) | 20.0-update3771 (including) |
Deep_security_agent | Trendmicro | 20.0-update3964 (including) | 20.0-update3964 (including) |
Deep_security_agent | Trendmicro | 20.0-update4185 (including) | 20.0-update4185 (including) |
Deep_security_agent | Trendmicro | 20.0-update4416 (including) | 20.0-update4416 (including) |
Deep_security_agent | Trendmicro | 20.0-update4726 (including) | 20.0-update4726 (including) |
Deep_security_agent | Trendmicro | 20.0-update4959 (including) | 20.0-update4959 (including) |
Deep_security_agent | Trendmicro | 20.0-update5137 (including) | 20.0-update5137 (including) |
Deep_security_agent | Trendmicro | 20.0-update5394 (including) | 20.0-update5394 (including) |
Deep_security_agent | Trendmicro | 20.0-update5512 (including) | 20.0-update5512 (including) |
Deep_security_agent | Trendmicro | 20.0-update5810 (including) | 20.0-update5810 (including) |
Deep_security_agent | Trendmicro | 20.0-update5995 (including) | 20.0-update5995 (including) |
Deep_security_agent | Trendmicro | 20.0-update6313 (including) | 20.0-update6313 (including) |
Deep_security_agent | Trendmicro | 20.0-update6690 (including) | 20.0-update6690 (including) |
Deep_security_agent | Trendmicro | 20.0-update6860 (including) | 20.0-update6860 (including) |
Deep_security_agent | Trendmicro | 20.0-update7119 (including) | 20.0-update7119 (including) |
Deep_security_agent | Trendmicro | 20.0-update7303 (including) | 20.0-update7303 (including) |
Deep_security_agent | Trendmicro | 20.0-update7476 (including) | 20.0-update7476 (including) |
Deep_security_agent | Trendmicro | 20.0-update7719 (including) | 20.0-update7719 (including) |
Deep_security_agent | Trendmicro | 20.0-update7943 (including) | 20.0-update7943 (including) |
Deep_security_agent | Trendmicro | 20.0-update8137 (including) | 20.0-update8137 (including) |
Deep_security_agent | Trendmicro | 20.0-update8268 (including) | 20.0-update8268 (including) |
Deep_security_agent | Trendmicro | 20.0-update877 (including) | 20.0-update877 (including) |