CVE Vulnerabilities

CVE-2024-36358

Insufficient Use of Symbolic Constants

Published: Jun 10, 2024 | Modified: Oct 23, 2025
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A link following vulnerability in Trend Micro Deep Security 20.x agents below build 20.0.1-3180 could allow a local attacker to escalate privileges on affected installations.

Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.

Weakness

The source code uses literal constants that may need to change or evolve over time, instead of using symbolic constants.

Affected Software

Name Vendor Start Version End Version
Deep_security_agent Trendmicro 20.0-update1194 (including) 20.0-update1194 (including)
Deep_security_agent Trendmicro 20.0-update1304 (including) 20.0-update1304 (including)
Deep_security_agent Trendmicro 20.0-update1337 (including) 20.0-update1337 (including)
Deep_security_agent Trendmicro 20.0-update1559 (including) 20.0-update1559 (including)
Deep_security_agent Trendmicro 20.0-update1681 (including) 20.0-update1681 (including)
Deep_security_agent Trendmicro 20.0-update1822 (including) 20.0-update1822 (including)
Deep_security_agent Trendmicro 20.0-update1876 (including) 20.0-update1876 (including)
Deep_security_agent Trendmicro 20.0-update2009 (including) 20.0-update2009 (including)
Deep_security_agent Trendmicro 20.0-update2204 (including) 20.0-update2204 (including)
Deep_security_agent Trendmicro 20.0-update2395 (including) 20.0-update2395 (including)
Deep_security_agent Trendmicro 20.0-update2593 (including) 20.0-update2593 (including)
Deep_security_agent Trendmicro 20.0-update2971 (including) 20.0-update2971 (including)
Deep_security_agent Trendmicro 20.0-update3165 (including) 20.0-update3165 (including)
Deep_security_agent Trendmicro 20.0-update3288 (including) 20.0-update3288 (including)
Deep_security_agent Trendmicro 20.0-update3445 (including) 20.0-update3445 (including)
Deep_security_agent Trendmicro 20.0-update3770 (including) 20.0-update3770 (including)
Deep_security_agent Trendmicro 20.0-update4185 (including) 20.0-update4185 (including)
Deep_security_agent Trendmicro 20.0-update4416 (including) 20.0-update4416 (including)
Deep_security_agent Trendmicro 20.0-update4726 (including) 20.0-update4726 (including)
Deep_security_agent Trendmicro 20.0-update4959 (including) 20.0-update4959 (including)
Deep_security_agent Trendmicro 20.0-update5137 (including) 20.0-update5137 (including)
Deep_security_agent Trendmicro 20.0-update5394 (including) 20.0-update5394 (including)
Deep_security_agent Trendmicro 20.0-update5512 (including) 20.0-update5512 (including)
Deep_security_agent Trendmicro 20.0-update5761 (including) 20.0-update5761 (including)
Deep_security_agent Trendmicro 20.0-update5953 (including) 20.0-update5953 (including)
Deep_security_agent Trendmicro 20.0-update6313 (including) 20.0-update6313 (including)
Deep_security_agent Trendmicro 20.0-update6658 (including) 20.0-update6658 (including)
Deep_security_agent Trendmicro 20.0-update6912 (including) 20.0-update6912 (including)
Deep_security_agent Trendmicro 20.0-update7119 (including) 20.0-update7119 (including)
Deep_security_agent Trendmicro 20.0-update7303 (including) 20.0-update7303 (including)
Deep_security_agent Trendmicro 20.0-update7476 (including) 20.0-update7476 (including)
Deep_security_agent Trendmicro 20.0-update7719 (including) 20.0-update7719 (including)
Deep_security_agent Trendmicro 20.0-update7943 (including) 20.0-update7943 (including)
Deep_security_agent Trendmicro 20.0-update8137 (including) 20.0-update8137 (including)
Deep_security_agent Trendmicro 20.0-update8268 (including) 20.0-update8268 (including)
Deep_security_agent Trendmicro 20.0-update8438 (including) 20.0-update8438 (including)
Deep_security_agent Trendmicro 20.0-update8453 (including) 20.0-update8453 (including)
Deep_security_agent Trendmicro 20.0-update877 (including) 20.0-update877 (including)
Deep_security_agent Trendmicro 20.0.1-update690 (including) 20.0.1-update690 (including)

Extended Description

This issue makes it more difficult to maintain the product, which indirectly affects security by making it more difficult or time-consuming to find and/or fix vulnerabilities. It also might make it easier to introduce vulnerabilities.

References